Description
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
Published: 2026-07-23
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control flaw that existed in Mediavine Control Panel plugin versions up to 2.10.10. It allows an attacker to invoke privileged plugin functions without proper authorization, potentially enabling unauthorized configuration changes, data exposure, or persistence. The weakness is classified as CWE‑862.

Affected Systems

WordPress sites that have the Mediavine Control Panel plugin version 2.10.10 or earlier installed. Administrators using these plugin versions are at risk. The plugin is typically distributed via WordPress.org and is used by sites that work with the Mediavine ad network.

Risk and Exploitability

The CVSS base score of 4.3 places the flaw in the moderate range. The EPSS score indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the broken access control description, the likely attack vector is that an attacker who can authenticate to the WordPress site—either through credential compromise or social engineering—could trigger privileged plugin functions via the Mediavine Control Panel endpoints without proper capability checks. The CVE description does not specify the exact conditions or endpoints, so the precise risk profile beyond the severity and low exploit probability remains uncertain. Security teams should treat it as a low‑priority issue but still apply the fix when possible.

Generated by OpenCVE AI on August 3, 2026 at 22:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Mediavine Control Panel plugin to the latest available version, which removes the broken access control flaw.
  • If an update is not yet available, delete or deactivate the plugin until a patch exists to prevent the vulnerability from being exploitable.
  • Restrict WordPress admin area access to trusted users only, and consider implementing additional role‑based access controls or security plugins that validate user capabilities before allowing plugin operations.

Generated by OpenCVE AI on August 3, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediavine
Mediavine mediavine Control Panel
Wordpress
Wordpress wordpress
Vendors & Products Mediavine
Mediavine mediavine Control Panel
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
Title WordPress Mediavine Control Panel plugin <= 2.10.10 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Mediavine Mediavine Control Panel
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:54:12.497Z

Reserved: 2026-02-02T12:53:34.261Z

Link: CVE-2026-25424

cve-icon Vulnrichment

Updated: 2026-07-23T13:54:41.570Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:17:13.927

Modified: 2026-07-23T16:17:16.753

Link: CVE-2026-25424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:45:04Z

Weaknesses