CVE-2026-104678: Unknown CP Media Player
Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
Affected products
- Unknown CP Media Player: before 1.3.4 (fixed in 1.3.4)
Published 2026-10-07. Last modified 2026-10-07.