First published: Sat Feb 15 2025(Updated: )
The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attackers, with Author-level access and above, to change plugin settings related to things such as IP-blocking.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Media Library Folders | <=8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0935 is considered a medium severity vulnerability due to the risk of unauthorized settings changes by authenticated attackers.
To fix CVE-2025-0935, you should update the Media Library Folders plugin to the latest version, beyond 8.3.0.
Authenticated users with Author-level access and above are affected by CVE-2025-0935.
CVE-2025-0935 allows attackers to change plugin settings without proper authorization, which can compromise site security.
A temporary workaround for CVE-2025-0935 is to limit user roles and permissions until the plugin is updated.