MEDIUM
Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure
Published Jul 11, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.41%
Description
The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API credentials.
Affected products
-
- Version 0StatusaffectedConstraints<=1.1.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| 2coders | Mux Video Uploader | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43128 Advisory
- https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/tags/1.1.4/includes/functions.php#L668
- https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/tags/1.1.4/includes/functions.php#L672
- https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/trunk/includes/functions.php#L668
- https://plugins.trac.wordpress.org/browser/2coders-integration-mux-video/trunk/includes/functions.php#L672
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3543763%402coders-integration-mux-video&new=3543763%402coders-integration-mux-video
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e462a7ba-887c-408d-87a6-9260a33dcff5?source=cve
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Jul 11, 2026
Updated Jul 13, 2026
Reserved Apr 30, 2026
Link CVE-2026-7544
CISA Vulnrichment
Updated Jul 13, 2026
ENISA EUVD
EUVD-2026-43128 Assigner Wordfence
Published Jul 11, 2026
Updated Jul 13, 2026
Exploited since n/a
Link EUVD-2026-43128