CVE · Medium

CVE-2023-0293 — Mediamatic – Media Library Folders [mediamatic] <= 2.8.1 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0293 Mediamatic – Media Library Folders [mediamatic] <= 2.8.1 (unfixed) Missing Authorization Medium 4.3 < 2.8.1 2.8.1 2022-12-14

CVE-2023-0293

The Mediamatic – Media Library Folders plugin through version 2.8.1 contains an authorization bypass vulnerability in its AJAX handlers that lack proper capability validation. Attackers with authenticated subscriber accounts or higher privileges can exploit this flaw to modify image categories used for organizing files in folder views. The issue remains unpatched in all currently available versions of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.