CVE-2025-0935: Media Library Folders <= 8.3.0 - Missing Authorization to Plugin Settings Change

Medium (4.3)

Sign up for FREE to recieve instant alerts about this vulnerability!

Description

The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attackers, with Author-level access and above, to change plugin settings related to things such as IP-blocking.

Classification

CVE ID: CVE-2025-0935

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected Products

Vendor: maxfoundry

Product: Media Library Folders

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 0.24649 (how common is this exploit)

EPSS Date: 2025-03-13 (when was this score calculated)

Timeline