Junglewise Threat Intelligence

CVE-2026-7544: 2coders Mux Video Uploader sensitive information exposure in muxvideo_enqueue_settings_script

CVE-2026-7544 · Severity: medium · CVSS 4.3 · Published 2026-07-11

Executive brief

The Mux Video Uploader plugin for WordPress, which allows users to integrate Mux video services into their websites, contains a security flaw that exposes sensitive information. An attacker with a basic user account on the site could access private Mux API credentials. This could allow an unauthorized person to manage or access video content and services associated with the site's Mux account.

Technical details

The Mux Video Uploader plugin for WordPress suffers from an information exposure vulnerability (CWE-200) within the 'muxvideo_enqueue_settings_script' function. The vulnerability arises because sensitive configuration data, specifically Mux API credentials, are enqueued in a manner that makes them accessible to any authenticated user. An attacker with low-privileged access (Subscriber level or higher) can intercept these settings to extract the API keys. This is a network-based attack that does not require user interaction. The issue affects all versions up to 1.1.4; users should update to the latest patched version if available.

Affected products

  • 2coders Mux Video Uploader up to, and including, 1.1.4

Timeline

  • 2026-07-11: advisory: NVD publication date
  • 2026-07-11: disclosed: Wordfence disclosure date

References