๐Ÿ” CVE Alert

CVE-2026-104678

UNKNOWN 0.0

CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.

Vendor unknown
Product cp media player
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown cp media player

Be the first to know when new unknown vulnerabilities affecting unknown cp media player are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / CP Media Player
0 < 1.3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d650ea4e-62f9-48a0-8cb3-e6761a95eeaa/

Credits

Ryan Fabella WPScan