Description
The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API credentials.
Published: 2026-07-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Mux Video Uploader plugin for WordPress contains a flaw in the muxvideo_enqueue_settings_script function that can grant authenticated attackers with subscriber‑level access and higher the ability to read sensitive data, including Mux API credentials.

Affected Systems

WordPress sites that install the 2coders Mux Video Uploader plugin version 1.1.4 or earlier are affected. Any user with subscriber or higher role on those installations can trigger the vulnerability.

Risk and Exploitability

The CVSS score of 4.3 classifies it as moderate, and the EPSS score of less than 1% indicates a low probability of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the WordPress site with at least subscriber permissions; once logged in, the attacker can load the vulnerable script and capture the exposed credentials.

Generated by OpenCVE AI on July 31, 2026 at 12:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the 2coders Mux Video Uploader plugin to a version newer than 1.1.4, which removes the vulnerability.
  • Modify the plugin’s enqueue logic so that only users with administrator capabilities can trigger the settings script, effectively restricting subscriber‑level users from accessing the exposed data.
  • If an immediate update not possible, temporarily disable or remove the settings page or associated script to prevent credential disclosure until a patch is applied.

Generated by OpenCVE AI on July 31, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared 2coders
2coders mux Video Uploader
Wordpress
Wordpress wordpress
Vendors & Products 2coders
2coders mux Video Uploader
Wordpress
Wordpress wordpress

Sat, 11 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API credentials.
Title Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

2coders Mux Video Uploader
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-13T17:42:04.674Z

Reserved: 2026-04-30T18:53:02.173Z

Link: CVE-2026-7544

cve-icon Vulnrichment

Updated: 2026-07-13T17:41:49.072Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor