Sceawere

Vulnerability Detail

CVE-2026-62039UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Html5 Audio Player Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
bPlugins
Product
Html5 Audio Player
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player html5-audio-player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.8.8.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-09T12:17:10.810Z",
  "pubdate": "2026-10-09T12:17:10.810Z",
  "executiveSummary": "An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability, classified as Stored Cross-Site Scripting (XSS), has been identified in bPlugins Html5 Audio Player (html5-audio-player). This security flaw affects the product from version n/a through 2.8.8. The vulnerability resides in how the application processes and renders user-supplied input within its audio player configuration fields.\nBecause the input is not sanitized or neutralized before being stored in the database and subsequently rendered on the front-end, an attacker can inject malicious scripts. When an unsuspecting user or administrator visits a web page where the compromised audio player is loaded, the stored malicious script executes automatically within the context of their browser session. The risk implication is significant: attackers can hijack sessions, steal sensitive session cookies, perform unauthorized actions on behalf of the user, or deface the website. The primary impact is the compromise of confidentiality and integrity of user sessions on the affected WordPress site. No complex exploitation techniques are required, making this a high-risk issue for sites using vulnerable versions of the plugin.",
  "technicalDetails": "The underlying root cause of this vulnerability lies in the lack of robust input sanitization and output encoding mechanisms within the bPlugins Html5 Audio Player (html5-audio-player) WordPress plugin. Specifically, the vulnerability is classified under CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). This issue impacts all versions of the plugin from n/a through 2.8.8.\nDuring the normal operation of the plugin, users—potentially ranging from low-privileged contributors to high-privileged administrators depending on the specific site configuration—can create and configure audio players. The inputs provided during this process, which include audio source URLs, track titles, artist details, and layout settings, are stored in the application's database. The vulnerability manifests because the plugin fails to sanitize these inputs prior to database storage and subsequently fails to neutralize or escape them when generating the HTML output for frontend rendering.\nAn attacker exploits this flaw by injecting a malicious payload, typically a JavaScript snippet, into one of the vulnerable configuration fields. For instance, the attacker might append an event handler or a script tag, such as <svg onload=alert(1)> or a script referencing an external malicious loader, into a text input field associated with the audio player.\nThe attack flow proceeds as follows: First, the threat actor injects the payload into a persistent field within the html5-audio-player interface. Second, the WordPress application receives the request and commits the unvalidated data directly to the database. Third, a victim (an administrator, editor, or general site visitor) requests a webpage containing the rendered audio player. Fourth, the WordPress server queries the database, retrieves the raw malicious payload, and interpolates it directly into the response DOM. Finally, the victim’s browser renders the page, parses the injected script as executable code rather than passive text, and executes it immediately.\nThe post-exploitation capabilities are determined by the privilege level of the victim executing the script. If the victim is an administrator, the attacker can hijack their session token, perform unauthorized administrative tasks, alter site configuration, or execute cross-site request forgery (CSRF) exploits to gain permanent access. If the victim is an unauthenticated reader, the payload can be used for drive-by downloads, session hijacking, credential harvesting, or redirecting user traffic to malicious external domains."
}
CVE-2026-62039: Html5 Audio Player Stored XSS (MEDIUM Severity, CVSS: 6.5) | Sceawere