CVE-2026-11974

🟡 Monitoruj

Brak walidacji parametrów w wtyczce wp-media-folder-addon umożliwia ujawnienie plików i ataki SSRF.

CVSS
8.6
EPSS
0.5%
Exploit
none
Vendor
Opis źródłowy (NVD)

The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.

ssrf Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.6
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2026-07-29 07:16:41 UTC
Ostatnia modyfikacja (NVD)2026-08-10 13:17:52 UTC
Referencje