CVE-2026-104678: Unknown CP Media Player

Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.

Affected products

  • Unknown CP Media Player: before 1.3.4 (fixed in 1.3.4)

Published 2026-10-07. Last modified 2026-10-07.