๐Ÿ” CVE Alert

CVE-2026-11974

UNKNOWN 0.0

Media folder Addon <= 4.1.6 - Unauthenticated Arbitrary File Download

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.

Vendor unknown
Product wp-media-folder-addon
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp-media-folder-addon

Be the first to know when new unknown vulnerabilities affecting unknown wp-media-folder-addon are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / wp-media-folder-addon
0 โ‰ค 4.1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7b6aea5d-2e2e-4920-9776-b15841ba1f26/

Credits

Erwan LR (WPScan) WPScan