Critical severity9.8NVD Advisory· Published May 13, 2019· Updated Jun 17, 2026No known patch
CVE-2019-9618
No known patch is available for this vulnerability.
The affected plugin has been removed from the WordPress.org directory (reason: Security Issue), and no patched version is being distributed through the official directory. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
CVE-2019-9618
Description
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- GraceMedia/Media Player plugindescription
- Range: <=1.0
Patches
Vulnerability mechanics
References
4- seclists.org/fulldisclosure/2019/Mar/26nvdExploitMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2019/Mar/32nvdMailing ListThird Party Advisory
- wordpress.org/plugins/gracemedia-media-player/nvdRelease NotesThird Party Advisory
- wpvulndb.com/vulnerabilities/9234nvd
News mentions
0No linked articles in our index yet.