What the vulnerability does
01Description
Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.
Explanation of Vulnerability in Simple Terms
WP Media Folder versions up to 5.7.2 lack proper authorization checks, allowing authenticated users to modify or delete files and folders they should not have access to. An attacker with a low-privilege account can alter site content or disrupt media organization without proper permission validation. Update to a version newer than 5.7.2 to resolve this issue.
What an attacker can do
Modify or delete media files and folders belonging to other users or restricted areas.
Potential impact on your site
Unauthorized users can corrupt, delete, or alter your media library, potentially disrupting site content and user experience.
Conditions required to exploit
Attacker must have a valid WordPress user account with at least low-level privileges.
Key dates
External resources
Related vulnerabilities