← Vulnerability feed

Vulnerability record · CVE-2020-5742 · published 15 June 2020

CVE-2020-5742: Plex media server vulnerability

Plex · Media Server

Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.

8.8 CVSS 3.1 High EPSS 1.4% · top 28.3%
8.8CVSS 3.1 base score, v2 6.8
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5742 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2020-5741Plex Media Server Windows deserialization leads to Python code executionPlex Media Server on Windows deserializes untrusted data, allowing a remote, authenticated attacker to execute arbitrary Python code. The flaw is a C…KEVEPSS 73%analysed9.8CVE-2018-13415Plex media server xml external entity (xxe) vulnerabilityIn Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.…EPSS 32%8.8CVE-2019-19141Plex media server path traversal vulnerabilityThe Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account r…EPSS 4.7%7.8CVE-2020-5740Plex media server uncontrolled search path element vulnerabilityImproper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privi…EPSS 0.75%7.5CVE-2021-33959Plex media server origin validation error vulnerabilityPlex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.EPSS 15%7.5CVE-2014-9304Plex media server permissions and access controls vulnerabilityPlex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrati…EPSS 8.1%7.1CVE-2025-69414Plex media server incorrect authorization vulnerabilityPlex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.EPSS 0.25%7.1CVE-2025-69415Plex media server vulnerabilityIn Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the devic…EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2020-5742), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.