Executive brief
A security flaw in the JW Player plugin for WordPress could allow users with low-level access to bypass security restrictions. This plugin is used to integrate video playback into WordPress sites, and an exploit could allow unauthorized changes to video settings or access to restricted content. Organizations should update the plugin to prevent unauthorized users from interfering with site operations or viewing protected media.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the ilGhera JW Player for WordPress plugin (jw-player-7-for-wp) up to version 2.3.8. The flaw stems from insufficient access control checks on certain functions, which allows an authenticated attacker with low-level privileges (such as a Contributor) to execute actions or access data that should be restricted to higher-privileged users. The vulnerability is reachable over the network without user interaction. A patch is available in version 2.3.9.
Affected products
- ilGhera JW Player for WordPress (jw-player-7-for-wp) <= 2.3.8
Timeline
- 2026-01-11: other: Reported by researcher Nabil Irawan
- 2026-02-10: patched: Patch released in version 2.3.9
- 2026-04-08: disclosed: Initial CVE publication