CVE-2025-0935

The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attackers, with Author-level access and above, to change plugin settings related to things such as IP-blocking.
Configurations

Configuration 1 (hide)

cpe:2.3:a:maxfoundry:media_library_folders:*:*:*:*:*:wordpress:*:*

History

24 Feb 2025, 12:23

Type Values Removed Values Added
First Time Maxfoundry media Library Folders
Maxfoundry
CPE cpe:2.3:a:maxfoundry:media_library_folders:*:*:*:*:*:wordpress:*:*
Summary
  • (es) El complemento Media Library Folders para WordPress es vulnerable a cambios no autorizados en la configuración del complemento debido a una falta de verificación de capacidad en varias acciones AJAX en todas las versiones hasta la 8.3.0 incluida. Esto permite que atacantes autenticados, con acceso de nivel de autor y superior, cambien la configuración del complemento relacionada con cuestiones como el bloqueo de IP.
References () https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L6296 - () https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L6296 - Product
References () https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L697 - () https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L697 - Product
References () https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L7198 - () https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L7198 - Product
References () https://plugins.trac.wordpress.org/changeset/3234676/media-library-plus/trunk/media-library-plus.php - () https://plugins.trac.wordpress.org/changeset/3234676/media-library-plus/trunk/media-library-plus.php - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/6f810102-cf25-4898-a3a6-3cdc9a96aaea?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/6f810102-cf25-4898-a3a6-3cdc9a96aaea?source=cve - Third Party Advisory

15 Feb 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-15 09:15

Updated : 2025-02-24 12:23


NVD link : CVE-2025-0935

Mitre link : CVE-2025-0935

CVE.ORG link : CVE-2025-0935


JSON object : View

Products Affected

maxfoundry

  • media_library_folders
CWE
CWE-862

Missing Authorization