What the vulnerability does
01Description
Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.
Explanation of Vulnerability in Simple Terms
WP Media Folder versions up to 5.7.2 lack proper authorization checks, allowing authenticated users with low privileges to modify content they should not have access to. An attacker with a basic user account can alter files or settings through the plugin's interface without proper permission validation. This affects WordPress sites using the plugin where user roles and capabilities are not properly enforced.
What an attacker can do
Modify files or plugin settings without proper authorization as a low-privilege authenticated user.
Potential impact on your site
Unauthorized users can alter media folder contents or plugin configuration, potentially corrupting site data or changing settings.
Conditions required to exploit
Attacker must have a valid WordPress user account with low privileges (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities