Executive brief
FluentPlayer Pro is a WordPress plugin that provides video player functionality to website administrators. A broken access control vulnerability allows users with the Editor role to access or modify pages and content they should not be permitted to, potentially exposing or altering sensitive site data.
Technical details
The vulnerability is a broken access control flaw in the FluentPlayer Pro WordPress plugin affecting versions up to 1.3.2. Users with the Editor privilege level can bypass authorization checks to access or perform actions on pages and content beyond their intended scope. The vulnerability requires an authenticated attacker with Editor role credentials. Exploitation allows unauthorized access to restricted content or administrative functionality. The issue was patched in version 1.4.0.
Affected products
- ManageNinja LLC FluentPlayer Pro <= 1.3.2
Timeline
- 2026-08-26: disclosed: Published by Patchstack
- 2026-08-26: patched: Patched in version 1.4.0