Media from FTP <= 11.16 - Authenticated (Author+) Improper Privilege Management
medium
The Media from FTP plugin for WordPress is vulnerable to improper privilege management due to an insufficient capability check on the plugin's menu pages in versions up to, and including, 11.16. This makes it possible for authenticated attackers, with author-level permissions and above, to modify plugin settings on mul...
- CVSS:
- 6.3
- Affected:
- up to 11.16
- Fixed in:
- 11.17
- Disclosed:
- Aug 14, 2023
CVE-2023-4019 on NVD →
Media from FTP <= 11.15 - Improper Privilege Management
medium
The Media from FTP plugin for WordPress is vulnerable to improper privilege management due to an insufficient capability check on the plugin's menu pages in versions up to, and including, 11.15. This makes it possible for authenticated attackers with author-level permissions to modify plugin settings.
- CVSS:
- 6.3
- Affected:
- up to 11.16
- Fixed in:
- 11.16
- Disclosed:
- Jul 31, 2023
Media from FTP Plugin < 9.85 - Directory Traversal
high
The Media from FTP Plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 9.84 via the searchdir parameter to the wp-admin/admin.php?page=mediafromftp-search-register URI. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain...
- CVSS:
- 7.5
- Affected:
- up to 9.85
- Fixed in:
- 9.85
- Disclosed:
- Nov 13, 2018
CVE-2018-5310 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database