Impact
The FluentPlayer Pro plugin up to version 1.3.2 contains a broken access control flaw that allows unauthorized users to perform editor functions. This vulnerability can lead to unintended modifications of content, settings, or media entries within the plugin’s interface, effectively granting elevated privileges to improper actors. The weakness is classified as CWE-862, reflecting a failure to enforce proper authorization checks.
Affected Systems
The affected product is WP Manage Ninja’s FluentPlayer Pro plugin, versions 1.3.2 and earlier. The vulnerability is present in all releases of the plugin prior to 1.4.0, regardless of WordPress site version. No other components or products are reported to be impacted.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity, primarily affecting the plugin’s confidentiality, integrity, and availability. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been documented. Exploitation would require access to the plugin’s administrative interface; attackers who can authenticate as an editor or administrator could leverage the missing permission checks to modify or delete content. Given the moderate CVSS and lack of publicly known exploits, the risk is considered moderate but actionable.
OpenCVE Enrichment