CVE · Medium

CVE-2022-47142 — Mediamatic – Media Library Folders [mediamatic] <= 2.8.1 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-47142 Mediamatic – Media Library Folders [mediamatic] <= 2.8.1 (unfixed) Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.0 3.0 2023-01-13

CVE-2022-47142

The Mediamatic – Media Library Folders plugin through version 2.8.1 contains an unfixed cross-site request forgery vulnerability that allows attackers to trick authenticated users with higher privileges into performing unintended actions, such as changing account passwords, which could lead to unauthorized admin access. The plugin was closed on December 12, 2022 and remains unavailable while undergoing review. No patch has been released to address this security flaw.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.