CVE · Medium

CVE-2026-45442 — Presto Player [presto-player] < 4.1.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-45442 Presto Player [presto-player] < 4.1.4 Missing Authorization Medium 4.3 < 4.1.4 4.1.4 2026-05-19

CVE-2026-45442

The Presto Player plugin for WordPress, in versions up to and including 4.1.3, lacks a necessary security check for a specific function, allowing unauthorized users to execute an action without proper authentication. This flaw enables unauthenticated attackers to perform an action they shouldn't be able to, posing a security risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.