Executive brief
The Mux Video Uploader plugin for WordPress, which allows users to integrate Mux video services into their websites, contains a security flaw that exposes sensitive information. An attacker with a basic user account on the site could access private Mux API credentials. This could allow an unauthorized person to manage or access video content and services associated with the site's Mux account.
Technical details
The Mux Video Uploader plugin for WordPress suffers from an information exposure vulnerability (CWE-200) within the 'muxvideo_enqueue_settings_script' function. The vulnerability arises because sensitive configuration data, specifically Mux API credentials, are enqueued in a manner that makes them accessible to any authenticated user. An attacker with low-privileged access (Subscriber level or higher) can intercept these settings to extract the API keys. This is a network-based attack that does not require user interaction. The issue affects all versions up to 1.1.4; users should update to the latest patched version if available.
Affected products
- 2coders Mux Video Uploader up to, and including, 1.1.4
Timeline
- 2026-07-11: advisory: NVD publication date
- 2026-07-11: disclosed: Wordfence disclosure date
References
- https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/tags/1.1.4/includes/functions.php
- https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/tags/1.1.4/includes/functions.php
- https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/trunk/includes/functions.php
- https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/trunk/includes/functions.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3543763%402coders-integration-mux-video&new=3543763%402coders-integration-mux-video
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e462a7ba-887c-408d-87a6-9260a33dcff5?source=cve