CVE-2025-0935: Maxfoundry Media Library Folders

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attackers, with Author-level access and above, to change plugin settings related to things such as IP-blocking.

Affected products

  • Maxfoundry Media Library Folders: before 8.3.1 (fixed in 8.3.1)

Published 2025-02-15. Last modified 2026-06-17.