Vulnerability in HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player — CVE-2026-62039
MediumSeverity
—Estimated exploit probability
10,000+ sitesInstalls
Not publishedFixed in
What to do now
No fix has been published yet. Consider disabling HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player for now, or moving to an alternative.
Affected versions
- Everything up to and including 2.8.8
Affected: HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player (plugin, html5-audio-player)
What the vulnerability is
The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.8.8. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.