The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file in all versions up to, and including, 8.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several actions related to managing media files and folder along with controlling settings.
References
Configurations
History
No history.
Information
Published : 2024-08-30 10:15
Updated : 2024-09-03 14:34
NVD link : CVE-2024-7858
Mitre link : CVE-2024-7858
CVE.ORG link : CVE-2024-7858
JSON object : View
Products Affected
maxfoundry
- media_library_folders
CWE
CWE-862
Missing Authorization