CVE-2024-7858

The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file in all versions up to, and including, 8.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several actions related to managing media files and folder along with controlling settings.
Configurations

Configuration 1 (hide)

cpe:2.3:a:maxfoundry:media_library_folders:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-08-30 10:15

Updated : 2024-09-03 14:34


NVD link : CVE-2024-7858

Mitre link : CVE-2024-7858

CVE.ORG link : CVE-2024-7858


JSON object : View

Products Affected

maxfoundry

  • media_library_folders
CWE
CWE-862

Missing Authorization