WP Media folder <= 5.7.2 - Authenticated (Subscriber+) Arbitrary File Upload
high
The WP Media folder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server w...
- CVSS:
- 8.8
- Affected:
- up to 5.7.2
- Fixed in:
- 5.7.3
- Disclosed:
- Feb 15, 2024
CVE-2024-25909 on NVD →
WP Media folder <= 5.7.2 - Missing Authorization to Authenticated(Subscriber+) Title Modification
medium
The wp-media-folder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with subscriber access and above, to modify titles of posts and pages.
- CVSS:
- 4.3
- Affected:
- up to 5.7.2
- Fixed in:
- 5.7.3
- Disclosed:
- Feb 12, 2024
CVE-2024-25908 on NVD →
WP Media folder <= 5.7.2 - Missing Authorization to Authenticated(Subscriber+) Plugin settings change
medium
The wp-media-folder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with subscriber access and above, to change the plugin's settings.
- CVSS:
- 4.3
- Affected:
- up to 5.7.2
- Fixed in:
- 5.7.3
- Disclosed:
- Feb 12, 2024
CVE-2024-25907 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database