CVE-2026-2312
- EPSS 0.01%
- Veröffentlicht 14.02.2026 11:24:28
- Zuletzt bearbeitet 18.02.2026 17:52:44
The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.3.6 via the delete_maxgalleria_media() and maxgalleria_rename_image() functions due to missing validation on a us...
CVE-2025-0935
- EPSS 0.14%
- Veröffentlicht 15.02.2025 09:15:10
- Zuletzt bearbeitet 24.02.2025 12:23:14
The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attack...
CVE-2024-7858
- EPSS 0.13%
- Veröffentlicht 30.08.2024 10:15:07
- Zuletzt bearbeitet 03.09.2024 14:34:09
The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file in all versions up to, and including, 8.2.3. This makes it possible for ...
CVE-2024-7857
- EPSS 0.57%
- Veröffentlicht 29.08.2024 03:15:05
- Zuletzt bearbeitet 13.03.2025 13:59:34
The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all versions up to, and including, 8.2.2 due to insufficient escaping on the user su...
CVE-2024-3615
- EPSS 1.1%
- Veröffentlicht 19.04.2024 03:15:06
- Zuletzt bearbeitet 12.03.2025 18:40:25
The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 8.2.0 due to insufficient input sanitization and output escaping. This makes it possible for un...
CVE-2024-31287
- EPSS 0.73%
- Veröffentlicht 10.04.2024 16:15:13
- Zuletzt bearbeitet 13.03.2025 00:45:32
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.8.
CVE-2024-30486
- EPSS 0.59%
- Veröffentlicht 29.03.2024 14:15:10
- Zuletzt bearbeitet 13.03.2025 02:00:09
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.7.
CVE-2022-41634
- EPSS 0.1%
- Veröffentlicht 18.11.2022 23:15:25
- Zuletzt bearbeitet 21.11.2024 07:23:32
Cross-Site Request Forgery (CSRF) vulnerability in Media Library Folders plugin <= 7.1.1 on WordPress.