CVE · Medium

CVE-2024-7317 — Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.0.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7317 Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.0.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.0.4 3.0.4 2024-08-05

CVE-2024-7317

The Folders plugin for WordPress contains a security flaw allowing malicious SVG files to be uploaded and executed on the site. Versions 3.0.3 and earlier are affected due to inadequate filtering of user input, enabling attackers with Contributor privileges or higher to inject scripts that run when users access the uploaded file.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.