VYPR

WP Media folder Addon

by WordPress

CVEs (2)

  • CVE-2026-11974HigJul 29, 2026
    risk 0.56cvss 8.6epss 0.00

    The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites…

  • CVE-2026-9690HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.