CVE-2026-78283: WordPress Music Player for WooCommerce plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability
Published Aug 27, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
Affected Software
1 affected component
WordPress Music Player for WooCommerce<=1.8.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Music Player for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 1.9.0
Event History
Aug 27, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No authentication is required. The attack vector is network-based, but exploitation requires user interaction.
2
Which deployments are affected?
Music Player for WooCommerce versions 1.8.9 and earlier are affected. The provided information does not identify any configuration prerequisite or a fixed version.
3
What impact could successful exploitation have?
Successful XSS could affect confidentiality, integrity, and availability at low impact levels, with the scope potentially extending beyond the vulnerable component.