CVE-2026-40808: WordPress Jetpack VideoPress plugin <= 3.6 - Broken Access Control vulnerability
Published Oct 10, 2026
·Updated
Subscriber Broken Access Control in Jetpack VideoPress <= 3.6 versions.
Affected Software
1 affected component
Automattic Jetpack VideoPress<=3.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Jetpack VideoPress pluginto a version that resolves this vulnerability.Fixed in 3.7
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness