Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026No known patch
Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure
No known patch is available for this vulnerability.
The affected plugin has not been updated on WordPress.org since before this CVE was disclosed; the latest installable version is still vulnerable. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
CVE-2026-7544
Description
The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API credentials.
Affected products
1- Range: <=1.1.4
Patches
Vulnerability mechanics
References
6- plugins.trac.wordpress.org/browser/2coders-integration-mux-video/tags/1.1.4/includes/functions.phpmitre
- plugins.trac.wordpress.org/browser/2coders-integration-mux-video/tags/1.1.4/includes/functions.phpmitre
- plugins.trac.wordpress.org/browser/2coders-integration-mux-video/trunk/includes/functions.phpmitre
- plugins.trac.wordpress.org/browser/2coders-integration-mux-video/trunk/includes/functions.phpmitre
- plugins.trac.wordpress.org/changesetmitre
- www.wordfence.com/threat-intel/vulnerabilities/id/e462a7ba-887c-408d-87a6-9260a33dcff5mitre
News mentions
0No linked articles in our index yet.