CVE · Medium

CVE-2024-10582 — Music Player for Elementor – Audio Player & Podcast Player [music-player-for-elementor] < 2.4.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10582 Music Player for Elementor – Audio Player & Podcast Player [music-player-for-elementor] < 2.4.2 Missing Authorization Medium 4.3 < 2.4.2 2.4.2 2024-11-14

CVE-2024-10582

The Music Player for Elementor plugin through version 2.4.1 contains a vulnerability in its import_mpfe_template() function that fails to verify user permissions before processing template imports. This allows any authenticated user, even those with basic Subscriber privileges, to import templates without proper authorization. The vulnerability was resolved in version 2.4.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.