PT-2025-43588 · WordPress · Azure Storage For Wordpress

Published

2025-10-24

·

Updated

2025-10-24

·

CVE-2025-10749

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Microsoft Azure Storage for WordPress plugin for WordPress versions up to and including 4.5.1
Description The software is susceptible to unauthorized arbitrary media deletion. This is a result of missing capability checks on the 'azure-storage-media-replace' AJAX action. Authenticated attackers with subscriber-level access or higher can delete arbitrary media files from the WordPress Media Library through the replace attachment parameter, provided they have access to the nonce, which is exposed to all authenticated users.
Recommendations Update Microsoft Azure Storage for WordPress plugin for WordPress to a version later than 4.5.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-10749

Affected Products

Azure Storage For Wordpress