Media Library Folders WordPress Plugin Missing Authorization Vulnerability in Settings Change

Vulnerability

A vulnerability exists in the Media Library Folders plugin for WordPress, all versions through 8.3.0, allowing unauthorized changes to plugin settings. This issue arises from a lack of proper capability checks on several AJAX actions, enabling authenticated attackers with Author-level access or higher to modify settings, including those related to IP blocking.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially allowing for misuse of IP-blocking features.

Remediation

Users are advised to update the Media Library Folders plugin to version 8.3.1 or a newer patched version.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
6.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.