CVE-2026-104678 PUBLISHED

CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update

Assigner: WPScan
Reserved: 02.10.2026 Published: 07.10.2026 Updated: 07.10.2026

The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.

Product Status

Vendor Unknown
Product CP Media Player
Versions Default: unaffected
  • affected from 0 to 1.3.4 (excl.)

Credits

  • Ryan Fabella finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE