← Back to CVE List
CVE-2026-104678NVD
Vulnerability Summary
The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
CVSS v3.1 Base Metrics — Score 2.7 (LOW)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityNone
Affected & Patched Versions
Not provided by NVD for this CVE.
Not provided by NVD for this CVE.