PT-2024-37194 · WordPress · Media Hygiene

Lucio Sá

·

Published

2024-07-08

·

Updated

2024-07-09

·

CVE-2024-5855

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress versions up to, and including, 3.0.1
Description: The issue is related to a missing capability check on the bulk action delete and delete single image call AJAX actions. This allows authenticated attackers with Subscriber-level access and above to delete arbitrary attachments. A nonce check was added in version 3.0.1, but a capability check was only added in version 3.0.2.
Recommendations: For versions up to, and including, 3.0.1, update to version 3.0.2 or later to resolve the issue. As a temporary workaround, consider disabling the bulk action delete and delete single image call AJAX actions until a patch is available. Restrict access to the bulk action delete and delete single image call AJAX actions to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-5855

Affected Products

Media Hygiene