๐Ÿ” CVE Alert

CVE-2026-11974

HIGH 8.6

Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download

CVSS Score
8.6
EPSS Score
0.5%
EPSS Percentile
39th

The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.

Vendor unknown
Product wp-media-folder-addon
Published Jul 29, 2026
Last Updated Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp-media-folder-addon

Be the first to know when new high vulnerabilities affecting unknown wp-media-folder-addon are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / wp-media-folder-addon
0 < 4.1.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7b6aea5d-2e2e-4920-9776-b15841ba1f26/

Credits

Erwan LR (WPScan) WPScan