Viewing 15 replies - 1 through 15 (of 20 total)
  • Hi, I’m receiving this same message. Please let us know if you intend (and when) to update the plugin.

    Plugin Author icc0rz

    (@icc0rz)

    We haven’t receive any messages or requests regarding this. Typically someone would reach out to the open-source project, make a CVS issue or similar. Claiming that something is insecure from behind a paywall makes me question the incentive here and also the credibility of the source. Of course, if there is an issue we would love to hear about it in order to verify that it’s legit and to be able to issue a fix for it.

    Thank you for informing us.

    Please see this report: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/h5p/interactive-content-h5p-1160-authenticated-contributor-stored-cross-site-scripting

    It also refers to Patchstack, which is probably the same report the person at the beginning of this chain is referring to.

    Thank you for looking into it. I also sent the same report to PJorgensen with your group an hour or so ago.

    I’m extremely relieved to know y’all are still kicking! 🙂 I’ve been using your stuff for years and love it.

    Thread Starter Deryck

    (@deryck)

    Understood. I would like to clarify that I have no affiliation with Patchstack whatsoever.

    I only reported a security issue that I became aware of as a user of the add-on and wanted to share it because security is very important.

    I now see that it has been reported in other sources, which confirms that the problem does indeed exist.

    Thank you for responding. I hope it can indeed be reviewed and resolved.

    I am very grateful for the work you do with the plugin.

    Plugin Author icc0rz

    (@icc0rz)

    It looks like these are just copies and references to patchstack.

    The patchstack report doesn’t include any clues on how to reproduce or PoC, it looks to be auto-generated by some software and never actually verified by a human. Reading online this seems to be a common tactic to bring value to the product that they’re selling. They’re not contributing anything back to the WP community and that is probably also why they are refused to sponsor WP events etc.

    Anyway, if anyone has access to patchstack and/or are able to see the details of this report(how to reproduce) we’ll be more than happy to look into it.
    Until a human party can verify that this is actuall an issue I think it’s safe to disregard the report.

    The company that hosts my sites has installed something call cPGuard to provide security checks on all sites.
    I have received a security warning CVE 6.4 about the h5p plugin.

    @dedide That’s not surprising. All those security checkers use the common resources mentioned above (like CVE.org) to learn about potential threats and warn users. That does not mean that a human being has checked the validity of that claim.

    All we know so far is that someone claims that there was something wrong, but H5P Group has not been informed about what that would be (see icc’s answer) and the potential confirmation/proof-of-concept is hidden behind a paywall. It could as well be a false positive created by letting a large language model run over code and just taking the result for granted without checking the validity of the claim.

    @icc0rz What happens when you try to “Claim ownership” in the details of the report on Patchstack? Will that reveal more information to you?

    Plugin Author icc0rz

    (@icc0rz)

    @otacke I’m waiting to be manually approved by their team.

    That sounds like progress! 👍

    Thank you all for your diligent work on this issue!

    Hi there, just want to add that this happening on my case too.

    H5P (1 vulnerability). Cross Site Scripting (XSS) vulnerability. Detected Oct 13 2025 in version <= 1.16.0.

    Heya! Any update on this one, @icc0rz ?

Viewing 15 replies - 1 through 15 (of 20 total)

The topic ‘H5P Plugin <= 1.16.0 is vulnerable to Cross Site’ is closed to new replies.