PT-2025-43588 · WordPress · Azure Storage For Wordpress

CVE-2025-10749

·

Published

2025-10-24

·

Updated

2025-10-24

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Microsoft Azure Storage for WordPress plugin for WordPress versions up to and including 4.5.1
Description The software is susceptible to unauthorized arbitrary media deletion. This is a result of missing capability checks on the 'azure-storage-media-replace' AJAX action. Authenticated attackers with subscriber-level access or higher can delete arbitrary media files from the WordPress Media Library through the replace attachment parameter, provided they have access to the nonce, which is exposed to all authenticated users.
Recommendations Update Microsoft Azure Storage for WordPress plugin for WordPress to a version later than 4.5.1.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10749

Affected Products

Azure Storage For Wordpress