CVE-2026-39614: WordPress JW Player for WordPress plugin <= 2.3.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in ilGhera JW Player for WordPress jw-player-7-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JW Player for WordPress: from n/a through <= 2.3.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ilGhera JW Player for WordPress (jw-player-7-for-wp)to a version that resolves this vulnerability.Fixed in 2.3.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39614?
CVE-2026-39614 is classified as a broken access control vulnerability which can lead to unauthorized actions within the JW Player for WordPress plugin.
How do I fix CVE-2026-39614?
To fix CVE-2026-39614, upgrade the JW Player for WordPress plugin to version 2.3.7 or later where this vulnerability is addressed.
What versions are affected by CVE-2026-39614?
CVE-2026-39614 affects all versions of JW Player for WordPress plugin up to and including version 2.3.6.
What kind of attacks can CVE-2026-39614 enable?
CVE-2026-39614 can enable unauthorized users to access restricted functionalities due to missing authorization checks.
Who is the vendor of the software affected by CVE-2026-39614?
The vendor of the affected software is ilGhera, specifically the JW Player for WordPress plugin.