Medium severity6.3NVD Advisory· Published Aug 30, 2024· Updated Jun 17, 2026
CVE-2024-7858
CVE-2024-7858
Description
The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file in all versions up to, and including, 8.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several actions related to managing media files and folder along with controlling settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:maxfoundry:media_library_folders:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:maxfoundry:media_library_folders:*:*:*:*:*:wordpress:*:*range: <8.2.4
- (no CPE)range: 0
- Range: <=8.2.3
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.