PT-2021-20636 · WordPress · Wordpress Real Media Library

Published

2021-08-30

·

Updated

2026-02-04

·

CVE-2021-34668

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: WordPress Real Media Library plugin versions up to and including 4.14.1
Description: The issue allows author-level attackers to inject arbitrary web scripts in folder names via the name parameter in the ~/inc/overrides/lite/rest/Folder.php file. This enables Stored Cross-Site Scripting attacks.
Recommendations: For WordPress Real Media Library plugin versions up to and including 4.14.1, update to a version later than 4.14.1 to resolve the issue. As a temporary workaround, consider restricting access to the ~/inc/overrides/lite/rest/Folder.php file to minimize the risk of exploitation. Avoid using the name parameter in the affected file until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-34668

Affected Products

Wordpress Real Media Library