PT-2026-57384 · WordPress · Mux Video Uploader
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mux Video Uploader versions prior to 1.1.5
Description
The Mux Video Uploader plugin for WordPress contains a flaw that allows authenticated users with subscriber-level access or higher to expose sensitive information. This occurs through the
muxvideo enqueue settings script function, enabling attackers to extract sensitive data such as Mux API credentials.Recommendations
Update the plugin to a version later than 1.1.4.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mux Video Uploader