CVE-2025-0865: WP Media Category Management 2.0 - 2.3.3 - Cross-Site Request Forgery to Settings Update
The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or incorrect nonce validation on the wpmcmhandleactionsettings() function. This makes it possible for unauthenticated attackers to alter plugin settings, such as the taxonomy used for media, the base slug for media categories, and the default media category via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0865?
CVE-2025-0865 is classified as a medium severity vulnerability due to its potential for exploitation through Cross-Site Request Forgery.
How do I fix CVE-2025-0865?
To mitigate CVE-2025-0865, you should update the WP Media Category Management plugin to version 2.3.4 or later.
Who is affected by CVE-2025-0865?
Users of the WP Media Category Management plugin for WordPress versions 2.0 to 2.3.3 are affected by CVE-2025-0865.
What causes CVE-2025-0865?
CVE-2025-0865 is caused by missing or incorrect nonce validation in the wp_mcm_handle_action_settings() function.
Can unauthenticated users exploit CVE-2025-0865?
Yes, unauthenticated attackers can exploit CVE-2025-0865 to perform unauthorized actions on the affected WordPress site.