CVE-2026-93512: WordPress JW Player for WordPress plugin <= 2.3.11 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JW Player for WordPress Pluginto a version that resolves this vulnerability.Fixed in 2.3.12
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation requires user interaction, as reflected by the UI:R vector.
Which installations are affected?
JW Player for WordPress versions 2.3.11 and earlier are identified as affected. The provided information does not state whether any particular WordPress configuration or plugin feature must be enabled.
What is the potential impact?
Successful XSS can affect confidentiality, integrity, and availability at low impact levels. The scope may extend beyond the vulnerable plugin component, as indicated by the S:C vector.