WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in HTML5 Video Player – embed fast, responsive videos with ease

Responsive HTML5 video player for WordPress. Embed MP4, WebM, OGG, YouTube & Vimeo with shortcodes or blocks – customizable, fast, SEO-friendly.

9Reported vulnerabilities
9.8Highest CVSS score
2.12.0Latest version
20,000+Active installs

What to do now

Update HTML5 Video Player – embed fast, responsive videos with ease to 2.11.1 or later. 9 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 4, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-1061 Critical 9.8 11.2% Before 2.5.25 2.5.25 January 30, 2024
CVE-2024-5522 Medium 6.5 2.6% Before 2.5.27 2.5.27 June 20, 2024
CVE-2023-6485 Medium 5.4 0.5% Before 2.5.19 2.5.19 January 1, 2024
CVE-2024-13156 Medium 6.4 0.4% 0 to 2.5.35 (inclusive) 2.5.36 January 14, 2025
CVE-2024-43296 Medium 6.4 0.4% 2.5.30 and earlier 2.5.31 August 16, 2024
CVE-2026-57323 Medium 5.3 0.3% 2.11.0 and earlier 2.11.1 June 26, 2026
CVE-2024-7727 Medium 5.3 0.4% Before 2.5.33 2.5.33 September 11, 2024
CVE-2024-7721 Medium 4.3 0.3% Before 2.5.35 2.5.35 September 11, 2024
CVE-2024-43319 Medium 4.3 0.4% 2.5.31 and earlier 2.5.32 August 16, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.