Media Sync
Media Sync has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.
The most common weakness is Path Traversal, behind 1 of the records (100%).
The one issue recorded for Media Sync has a vendor fix available, so running the current release closes it.
All of these findings were reported by Drew Webber (mcdruid). Media Sync is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-6670Media Sync <= 1.4.9 - Authenticated (Author+) Path Traversal via 'sub_dir' and 'media_items' Parameters
Read the full analysisVulnerability Records
Media Sync
Author
erolsk8
This plugin allows you to examine all files within the uploads directory to determine which ones are present in the Media Library and which ones are just sitting there unused. You can then choose the files you want to import into the database, thereby including them in the Media Library. Moreover, you can utilize FTP to upload files directly to the uploads directory and subsequently add these files to the Media Library avoiding any file size limitations. Disclaimers “1 file first” Please try to import only one file first – to see if it works as you expected. “All at once” This plugin is designed for scanning, selecting, and importing all files at once. However, based on your server’s configuration, memory, and timeout challenges may arise with extensive file quantities. To mitigate this, a newly revamped pro version employs incremental directory scans to effectively tackle these issues. “Your setup is unique” Please be aware that every WordPress installation is unique, and there may be instances where this plugin does not function as expected. Should this occur, we recommend enabling the debugging feature in the plugin’s settings to identify the issue. After investigating, kindly provide a detailed description of your findings in the Support section (or here if you’re using pro version). The more comprehensive the details, the higher the likelihood of resolving the problem effectively. Ignored files various hidden files (.DS_Store, .htaccess), WP generated thumbnails (files ending with for example -100×100.jpg), WP generated scaled images (files ending with -scaled), optimized .webp versions of original images (.jpg.webp), retina thumbnails (-100×100@2x.jpg). These can be modified and enhanced using the new advanced filters available in the pro version. Media Sync Pro features Revised incremental scan: Allows scanning and importing unlimited number of files. Quick single directory rescan: Easily rescan one directory to find new files or apply a different filter without reloading the whole page. Advanced filters: Find any file by customizing all default filters, search for a specific file type (images, videos, etc.), skip by tailor-made rules, or enter any custom pattern. Schedule automatic imports: Select a desired interval and let the plugin automatically import any new files it finds. Import logs: View the history of manual or scheduled imports. Limit plugin access: Limit plugin access to a specific role. Get pro version here.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C