SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-7544

MEDIUM · CVSS 4.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-11 · Last synced 2026-08-10

CyberRota Analysis

AI-Generated

The Mux Video Uploader plugin for WordPress is susceptible to sensitive information exposure, allowing authenticated attackers with subscriber-level access or higher to retrieve sensitive data, including Mux API credentials. This vulnerability affects all versions up to and including 1.1.4, posing a risk of unauthorized access to critical API information. WordPress site administrators using this plugin should prioritize updating to mitigate potential data breaches.

CVE
CVE-2026-7544
Severity
MEDIUM
CVSS
4.3
EPSS
0.24%
WordPress

Original NVD Description

The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API credentials.