HIGH
wp-media-folder-addon
CVE published 2026-07-29
CVE-2026-11974
The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users. This issue leads to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. The vulnerability has a CVSS score of 8.6 and is rated HIGH. Affected [truncated]