plugin

Wp Media Folder Vulnerabilities

3 known security issues reported for the Wp Media Folder WordPress plugin. Most recent disclosed Feb 15, 2024.

1 high 2 medium

Running Wp Media Folder on your site? Check whether your installed version is affected.

Scan your site free

WP Media folder <= 5.7.2 - Authenticated (Subscriber+) Arbitrary File Upload

high

The WP Media folder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server w...

CVSS:
8.8
Affected:
up to 5.7.2
Fixed in:
5.7.3
Disclosed:
Feb 15, 2024

CVE-2024-25909 on NVD →

WP Media folder <= 5.7.2 - Missing Authorization to Authenticated(Subscriber+) Title Modification

medium

The wp-media-folder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with subscriber access and above, to modify titles of posts and pages.

CVSS:
4.3
Affected:
up to 5.7.2
Fixed in:
5.7.3
Disclosed:
Feb 12, 2024

CVE-2024-25908 on NVD →

WP Media folder <= 5.7.2 - Missing Authorization to Authenticated(Subscriber+) Plugin settings change

medium

The wp-media-folder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with subscriber access and above, to change the plugin's settings.

CVSS:
4.3
Affected:
up to 5.7.2
Fixed in:
5.7.3
Disclosed:
Feb 12, 2024

CVE-2024-25907 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database