Executive brief
The Mediavine Control Panel plugin for WordPress, which helps site owners manage advertising and site settings, contains a security flaw in its access control mechanisms. This vulnerability allows users with 'Contributor' level permissions to perform actions they should not be authorized to access. While the impact is considered low, it could allow unauthorized changes to site configurations or settings.
Technical details
The Mediavine Control Panel plugin for WordPress (versions up to and including 2.10.10) suffers from a missing authorization check (CWE-862). This broken access control vulnerability allows an authenticated attacker with 'Contributor' level privileges to execute functions or modify settings that should be restricted to higher-privileged users. The attack is performed over the network without requiring user interaction. At the time of the advisory, no official patch has been released to address this issue.
Affected products
- Mediavine Mediavine Control Panel <= 2.10.10
Timeline
- 2025-12-28: other: Reported by researcher Nabil Irawan
- 2026-07-23: disclosed: CVE published to NVD dataset