Media from FTP <= 11.15 - Improper Privilege Management

2023-07-31 00:00
Marc-Alexandre Montpas

Strategic Overview

Status
Patched in 11.16
Affected PluginMedia from FTP
Affected Version< 11.16
CVSS6.3Medium
CVEN/A
View all Media from FTP vulnerabilities

Vulnerability Overview

The Media from FTP plugin for WordPress is vulnerable to improper privilege management due to an insufficient capability check on the plugin's menu pages in versions up to, and including, 11.15. This makes it possible for authenticated attackers with author-level permissions to modify plugin settings.

Technical Analysis

REMEDIATION: Update to version 11.16, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C