Unrated severityNVD Advisory· Published Oct 7, 2026
CVE-2026-104678
CVE-2026-104678
Description
The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.3.4
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.