PT-2025-6816 · WordPress · Media Library Folders

Brian Sans-Souci

+1

·

Published

2025-02-15

·

Updated

2025-02-24

·

CVE-2025-0935

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Media Library Folders plugin for WordPress versions up to, and including, 8.3.0
Description The issue is related to a missing capability check on several AJAX actions, allowing authenticated attackers with Author-level access and above to change plugin settings, such as IP-blocking.
Recommendations For versions up to, and including, 8.3.0, update to a version higher than 8.3.0 to resolve the issue. As a temporary workaround, consider restricting access to the AJAX actions related to plugin settings change until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-0935

Affected Products

Media Library Folders