PatchSiren

wp-media-folder-addon CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wp-media-folder-addon CVE published 2026-07-29

CVE-2026-11974

The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users. This issue leads to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. The vulnerability has a CVSS score of 8.6 and is rated HIGH. Affected [truncated]