Junglewise Threat Intelligence

CVE-2026-78281: CP Media Player unauthenticated cross-site scripting (XSS)

CVE-2026-78281 · Severity: high · CVSS 7.1 · Published 2026-08-27

Executive brief

CP Media Player is a WordPress plugin that enables audio and video playback on websites. Versions 1.3.0 and earlier contain an unauthenticated cross-site scripting vulnerability that allows attackers to inject malicious scripts into affected websites. Successful exploitation could enable attackers to steal visitor data, hijack user accounts, or perform unauthorized actions on behalf of visitors.

Technical details

The vulnerability is an unauthenticated cross-site scripting (XSS) flaw in CP Media Player plugin versions up to 1.3.0. The attack is classified as a stored or reflected XSS vulnerability that requires user interaction (e.g., clicking a malicious link or visiting a crafted page). No privileged access is required for the initial exploit vector, though the advisory notes that successful exploitation may require a privileged user to perform certain actions. The vulnerability was patched in version 1.3.1; vendors should update immediately to remediate the issue.

Affected products

  • CP Media Player CP Media Player ≤ 1.3.0

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Version 1.3.1 released

References