Impact
The Mux Video Uploader plugin for WordPress contains a flaw in the muxvideo_enqueue_settings_script function that can grant authenticated attackers with subscriber‑level access and higher the ability to read sensitive data, including Mux API credentials.
Affected Systems
WordPress sites that install the 2coders Mux Video Uploader plugin version 1.1.4 or earlier are affected. Any user with subscriber or higher role on those installations can trigger the vulnerability.
Risk and Exploitability
The CVSS score of 4.3 classifies it as moderate, and the EPSS score of less than 1% indicates a low probability of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the WordPress site with at least subscriber permissions; once logged in, the attacker can load the vulnerable script and capture the exposed credentials.
OpenCVE Enrichment