CVE-2024-2428
Estado: AnalizadaMedia (4.7)—
The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
- Puntuación base: 4.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.50%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-2428",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-2428",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-10-30T13:57:54.988821Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 4.7,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "contact@wpscan.com",
"affectedData": [
{
"vendor": "Unknown",
"product": "The Ultimate Video Player For WordPress ",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.2.3",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-04-10T05:15:49.070",
"references": [
{
"url": "https://wpscan.com/vulnerability/4832e223-4571-4b45-97db-2fd403797c49/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/4832e223-4571-4b45-97db-2fd403797c49/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks"
},
{
"lang": "es",
"value": "El complemento Ultimate Video Player For WordPress para WordPress anterior a 2.2.3 no tiene una verificación de capacidad adecuada al actualizar su configuración a través de una ruta REST, lo que permite a Contributor y a los usuarios superiores actualizarlos. Además, debido a la falta de escape en una de las configuraciones, esto también les permite realizar ataques XSS almacenados."
}
],
"lastModified": "2026-06-17T07:24:31.050",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:prestoplayer:presto_player:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "3F9CBCF2-8935-4630-ACD7-FC317A36C68B",
"versionEndExcluding": "2.2.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "contact@wpscan.com"
}