Media from FTP <= 11.16 - Authenticated (Author+) Improper Privilege Management
2023-08-14 00:00
Dmitrii IgnatyevStrategic Overview
StatusPatched in 11.17
Affected PluginMedia from FTP
Affected Version
<= 11.16CVSS6.3Medium
CVE
CVE-2023-4019Vulnerability Overview
The Media from FTP plugin for WordPress is vulnerable to improper privilege management due to an insufficient capability check on the plugin's menu pages in versions up to, and including, 11.16. This makes it possible for authenticated attackers, with author-level permissions and above, to modify plugin settings on multi-site installations.
Technical Analysis
REMEDIATION: Update to version 11.17, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C