Media from FTP <= 11.15 - Improper Privilege Management
2023-07-31 00:00
Marc-Alexandre MontpasStrategic Overview
Vulnerability Overview
The Media from FTP plugin for WordPress is vulnerable to improper privilege management due to an insufficient capability check on the plugin's menu pages in versions up to, and including, 11.15. This makes it possible for authenticated attackers with author-level permissions to modify plugin settings.
Technical Analysis
REMEDIATION: Update to version 11.16, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C