CVE-2026-104678
Received Received - Intake

Unauthorized Capability Escalation in CP Media Player WordPress Plugin

Vulnerability report for CVE-2026-104678, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: WPScan

Description

The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown CP Media Player 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the CP Media Player WordPress plugin before version 1.3.4 allows users with Contributor-level access to modify site-wide media player settings without proper authorization. The plugin fails to check user capabilities when handling settings, letting Contributors create, edit, duplicate, or delete media player configurations and change options that should require administrator access.

Detection Guidance

Check the installed version of the CP Media Player plugin in WordPress. If it is below 1.3.4, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the version.

Impact Analysis

If you are a WordPress site administrator, an attacker with Contributor-level access could misuse this flaw to alter media player settings across your site. This could lead to unauthorized changes in how media content is displayed, potentially disrupting user experience or embedding malicious content without your knowledge.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modifications to media player settings, which may result in improper handling of user data or media content. For GDPR, this could affect data integrity or user consent mechanisms. For HIPAA, unauthorized changes might compromise protected health information displayed via media players.

Mitigation Strategies

Update the CP Media Player plugin to version 1.3.4 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104678. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart