Executive brief
Presto Player is a video player plugin for WordPress used to manage and display video content. A security flaw in the plugin's access control settings allows users with low-level accounts to bypass intended restrictions. This could lead to unauthorized access to video content or settings that should be restricted to administrators.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Brainstorm Force Presto Player plugin for WordPress. The flaw resides in the handling of access control security levels, where the application fails to properly validate the permissions of a user before granting access to specific functionality or data. An attacker with low-privileged access (subscriber or contributor level) can exploit this to bypass intended restrictions. The issue affects all versions up to and including 4.1.3 and is resolved in version 4.1.4.
Affected products
- Brainstorm Force Presto Player up to 4.1.3
Timeline
- 2026-02-14: disclosed: Reported by Bao - BlueRock
- 2026-05-19: patched: Fixed in version 4.1.4
- 2026-05-19: advisory: Published by Patchstack and NVD