plugin

Real Media Library Lite Vulnerabilities

4 known security issues reported for the Real Media Library Lite WordPress plugin. Most recent disclosed Apr 15, 2024.

4 medium

Running Real Media Library Lite on your site? Check whether your installed version is affected.

Scan your site free

Real Media Library <= 4.22.11 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image title and alt text in all versions up to, and including, 4.22.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit...

CVSS:
6.4
Affected:
up to 4.22.11
Fixed in:
4.22.12
Disclosed:
Apr 15, 2024

CVE-2024-2328 on NVD →

Real Media Library: Media Library Folder & File Manager <= 4.22.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its style attributes in all versions up to, and including, 4.22.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contrib...

CVSS:
6.4
Affected:
up to 4.22.7
Fixed in:
4.22.8
Disclosed:
Mar 25, 2024

CVE-2024-2027 on NVD →

Real Media Library: Media Library Folder & File Manager <= 4.18.28 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via folder names in versions up to, and including, 4.18.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author-level permis...

CVSS:
6.4
Affected:
up to 4.18.28
Fixed in:
4.18.29
Disclosed:
Feb 2, 2023

CVE-2023-0285 on NVD →

WordPress Real Media Library <= 4.14.1 - Authenticated (Author) Stored Cross-Site Scripting

medium

The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in the ~/inc/overrides/lite/rest/Folder.php file which allows author-level attackers to inject arbitrary web scripts in folder names, in versions up to and including 4.14.1.

CVSS:
6.4
Affected:
up to 4.14.1
Fixed in:
4.14.2
Disclosed:
Aug 25, 2021

CVE-2021-34668 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database