The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attackers, with Author-level access and above, to change plugin settings related to things such as IP-blocking.
References
Configurations
History
24 Feb 2025, 12:23
Type | Values Removed | Values Added |
---|---|---|
First Time |
Maxfoundry media Library Folders
Maxfoundry |
|
CPE | cpe:2.3:a:maxfoundry:media_library_folders:*:*:*:*:*:wordpress:*:* | |
Summary |
|
|
References | () https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L6296 - Product | |
References | () https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L697 - Product | |
References | () https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L7198 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3234676/media-library-plus/trunk/media-library-plus.php - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/6f810102-cf25-4898-a3a6-3cdc9a96aaea?source=cve - Third Party Advisory |
15 Feb 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-15 09:15
Updated : 2025-02-24 12:23
NVD link : CVE-2025-0935
Mitre link : CVE-2025-0935
CVE.ORG link : CVE-2025-0935
JSON object : View
Products Affected
maxfoundry
- media_library_folders
CWE
CWE-862
Missing Authorization