CVE-2023-0285: Devowl Real Media Library

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

Affected products

  • Devowl Real Media Library: before 4.18.29 (fixed in 4.18.29)

Published 2023-02-21. Last modified 2026-06-17.