CVE-2024-25908: WordPress WP Media folder plugin <= 5.7.2 - Subscriber+ Arbitrary Post/Page Modification vulnerability
Published Mar 21, 2024
·Updated
Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.
Affected Software
1 affected component
JoomUnited WP Media folder<=5.7.2
Remediation
Information
Update to 5.7.3 or a higher version.
Event History
Mar 21, 2024
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverityWeakness
Apr 11, 2024
Data Sourced
via NVD·01:24 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25908?
CVE-2024-25908 has been classified as a missing authorization vulnerability that affects various versions of the JoomUnited WP Media folder.
2
How do I fix CVE-2024-25908?
To mitigate CVE-2024-25908, update the JoomUnited WP Media folder plugin to the latest version beyond 5.7.2.
3
What versions are affected by CVE-2024-25908?
CVE-2024-25908 affects all versions of the JoomUnited WP Media folder up to and including 5.7.2.
4
What impact does CVE-2024-25908 have on my site?
CVE-2024-25908 could allow unauthorized users to modify post titles and excerpts, potentially leading to content defacement.
5
Is my WordPress site at risk with CVE-2024-25908?
If you are using the JoomUnited WP Media folder plugin version 5.7.2 or earlier, your WordPress site is at risk from CVE-2024-25908.