Media folder Addon <= 4.1.6 - Unauthenticated Arbitrary File Read
high
The Media folder Addon plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.1.6. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 4.1.6
- Fix:
- No patched version reported
- Disclosed:
- Jul 8, 2026
CVE-2026-11974 on NVD →
Media folder Addon <= 4.0.1 - Unauthenticated Arbitrary File Download
critical
The Media folder Addon plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 9.1
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Jun 4, 2026
CVE-2026-9690 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database