CVE-2024-2428 — The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update — CVE Database · The Intelligence Room