CVE-2026-11974
🟡 Monitoruj
Brak walidacji parametrów w wtyczce wp-media-folder-addon umożliwia ujawnienie plików i ataki SSRF.
CVSS
8.6
EPSS
0.5%
Exploit
none
Vendor
Opis źródłowy (NVD)
The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.
ssrf
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.6 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2026-07-29 07:16:41 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-10 13:17:52 UTC |
Referencje
- https://wpscan.com/vulnerability/7b6aea5d-2e2e-4920-9776-b15841ba1f26/ (contact@wpscan.com)