Videojs HTML5 Player
Videojs HTML5 Player has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Videojs HTML5 Player has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Videojs HTML5 Player is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-5205Videojs HTML5 Player <= 1.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via videojs_video Shortcode
Read the full analysisVulnerability Records

Videojs HTML5 Player
Author
Noor Alam
Video.js HTML5 Player is a user-friendly plugin that supports video playback on desktop and mobile devices. It makes super easy for you to embed both self-hosted video files or video files that are externally hosted using Video.js library. Video.js HTML5 Player Add-ons Disable Right Click Themes Video.js HTML5 Player Features Embed MP4 video files into a post/page or anywhere on your WordPress site Embed responsive videos for a better user experience while viewing from a mobile device Embed HTML5 videos which are compatible with modern browsers Embed videos with poster images Embed videos using videojs player Automatically play a video when the page is rendered if the device and browser support it Embed videos uploaded to your WordPress media library using direct links in the shortcode Clean and sleek player with no watermark fallbacks for other HTML5-supported filetypes (WebM, Ogv) HTTP streaming How to Use Video.js HTML5 Player In order to embed a video create a new post/page and use the following shortcode: [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.mp4"] Here, “url” is the location of the MP4 video source file (H.264 encoded). You need to replace the sample URL with the actual URL of the video file. Video Shortcode Options The following options are supported in the shortcode. WebM You can specify a WebM video file in addition to the source MP4 video file. This parameter is optional. [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.mp4" webm="https://example.com/wp-content/uploads/videos/myvid.webm"] Ogv You can specify a Ogv video file in addition to the source MP4 & WebM video files. This parameter is optional. [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.mp4" webm="https://example.com/wp-content/uploads/videos/myvid.webm" ogv="https://example.com/wp-content/uploads/videos/myvid.ogv"] Width Defines the width of the video file (Height is automatically calculated). This option is not required unless you want to limit the maximum width of the video. [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.mp4" width="480"] Preload Specifies if and how the video should be loaded when the page loads. Defaults to “auto” (the video should be loaded entirely when the page loads). Other options: “metadata” – only metadata should be loaded when the page loads “none” – the video should not be loaded when the page loads [videojs_video url=”https://example.com/wp-content/uploads/videos/myvid.mp4″ preload=”metadata”] Controls Specifies that video controls should be displayed. Defaults to “true”. In order to hide controls set this parameter to “false”. [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.mp4" controls="false"] When you disable controls users will not be able to interact with your videos. So It is recommended that you enable autoplay for a video with no controls. Autoplay Causes the video file to automatically play when the page loads. [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.mp4" autoplay="true"] Poster Defines image to show as placeholder before the video plays. [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.mp4" poster="https://example.com/wp-content/uploads/poster.jpg"] Loop Causes the video file to loop to beginning when finished and automatically continue playing. [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.mp4" loop="true"] Muted Specifies that the audio output of the video should be muted. [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.mp4" muted="true"] Video.js HTTP Streaming The plugin supports the m3u8 file format that can be used for Video.js HTTP Streaming. It allows you to play HLS, DASH, and other HTTP streaming protocols with Video.js, even where they are not natively supported. [videojs_video url="https://example.com/wp-content/uploads/videos/myvid.m3u8"] For detailed documentation please visit the Videojs HTML5 Player plugin page
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C