CVE-2026-81272: WordPress FluentPlayer Pro plugin <= 1.3.2 - Broken Access Control vulnerability
Published Aug 27, 2026
·Updated
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
Affected Software
1 affected component
wordpress/fluentplayer-pro<=1.3.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress FluentPlayer Pro pluginto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Aug 27, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker must already have high-level privileges, as indicated by the PR:H vector. The issue is remotely reachable and does not require user interaction.
2
What is the likely security impact?
Successful exploitation can affect integrity, while confidentiality and availability are not identified as impacted. The CVSS vector rates the issue as medium severity with a score of 4.9.
3
Which plugin versions are affected?
FluentPlayer Pro versions up to and including 1.3.2 are affected. The provided data does not identify a fixed version or workaround.