CVE-2026-104678 - CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update
CVE ID :CVE-2026-104678
Published : Oct. 7, 2026, 7:16 a.m. | 29 minutes ago
Description :The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 7, 2026, 7:16 a.m. | 29 minutes ago
Description :The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...