CVE-2026-104678: CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update
The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CP Media Playerto a version that resolves this vulnerability.Fixed in 1.3.4
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with Contributor-level access can exploit the missing capability check. Administrator access is not required.
What can an attacker change?
A Contributor can create, modify, duplicate, or delete site-wide CP Media Player configurations. They can also change a plugin option that should be restricted to administrators.
Which deployments are affected?
CP Media Player versions earlier than 1.3.4 are affected. Exposure exists where untrusted or lower-privileged users have Contributor accounts.