CVE-2024-25907: WordPress WP Media folder plugin <= 5.7.2 - Plugin Settings Change vulnerability
Published Mar 21, 2024
·Updated
Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.
Affected Software
1 affected component
JoomUnited WP Media folder<=5.7.2
Remediation
Information
Update to 5.7.3 or a higher version.
Event History
Mar 21, 2024
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
RemedyDescriptionSeverityWeakness
Apr 11, 2024
Data Sourced
via NVD·01:24 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25907?
CVE-2024-25907 is classified as a missing authorization vulnerability, which can lead to unauthorized access to sensitive data.
2
How do I fix CVE-2024-25907?
To remediate CVE-2024-25907, update the JoomUnited WP Media Folder plugin to the latest version beyond 5.7.2.
3
Which versions are affected by CVE-2024-25907?
CVE-2024-25907 affects versions of the JoomUnited WP Media Folder plugin up to and including 5.7.2.
4
What are the potential impacts of CVE-2024-25907?
The potential impacts of CVE-2024-25907 include unauthorized access to media files and the possibility of data exposure.
5
Is CVE-2024-25907 specific to any platform?
Yes, CVE-2024-25907 specifically affects the JoomUnited WP Media Folder plugin on WordPress installations.