Impact
The vulnerability is a missing capability check in the CP Media Player WordPress plugin settings page. A user with Contributor level can create, modify, duplicate, and delete the site‑wide media player configurations and alter an option that should require administrator privileges. This is a classic example of broken access control (CWE‑285) and privilege escalation (CWE‑640). The attacker could alter plugin behavior, potentially redirect media playback or embed malicious content across the site, without gaining full admin rights, thereby impacting integrity and possibly user experience.
Affected Systems
WordPress installations running CP Media Player plugin versions older than 1.3.4 are affected. The plugin is distributed by an unknown vendor, but the issue exists in any site that has the plugin installed and a Contributor user role.
Risk and Exploitability
The vulnerability is exploitable by any authenticated user who has the Contributor role, which is a common role on WordPress sites. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, but the lack of a capability check creates a clear path for privilege escalation and misuse of the plugin configuration. The attack vector is HTTP requests to the plugin’s settings‑page handler, and no additional conditions are required beyond a Contributor‑level login. Given the widespread presence of WordPress sites and the commonality of the Contributor role, the risk level is moderate to high.
OpenCVE Enrichment