Description
The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized configuration changes through privilege escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing capability check in the CP Media Player WordPress plugin settings page. A user with Contributor level can create, modify, duplicate, and delete the site‑wide media player configurations and alter an option that should require administrator privileges. This is a classic example of broken access control (CWE‑285) and privilege escalation (CWE‑640). The attacker could alter plugin behavior, potentially redirect media playback or embed malicious content across the site, without gaining full admin rights, thereby impacting integrity and possibly user experience.

Affected Systems

WordPress installations running CP Media Player plugin versions older than 1.3.4 are affected. The plugin is distributed by an unknown vendor, but the issue exists in any site that has the plugin installed and a Contributor user role.

Risk and Exploitability

The vulnerability is exploitable by any authenticated user who has the Contributor role, which is a common role on WordPress sites. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, but the lack of a capability check creates a clear path for privilege escalation and misuse of the plugin configuration. The attack vector is HTTP requests to the plugin’s settings‑page handler, and no additional conditions are required beyond a Contributor‑level login. Given the widespread presence of WordPress sites and the commonality of the Contributor role, the risk level is moderate to high.

Generated by OpenCVE AI on October 7, 2026 at 07:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CP Media Player to version 1.3.4 or newer to enforce proper capability checks.
  • If an upgrade is not possible, block Contributor access to the plugin’s settings page using a capability filter or role‑management plugin.
  • Disable or remove CP Media Player from sites that do not require it, or restrict the plugin’s usage to Administrator users only.

Generated by OpenCVE AI on October 7, 2026 at 07:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-640

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
Title CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:06.122Z

Reserved: 2026-10-02T08:04:51.632Z

Link: CVE-2026-104678

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:58.363

Modified: 2026-10-07T07:16:58.363

Link: CVE-2026-104678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T07:30:14Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password