Cross-Site Request Forgery in Mediamatic Media Library Folders Plugin for WordPress
CVE-2023-0294
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 January 2023
What is CVE-2023-0294?
The Mediamatic – Media Library Folders plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) due to faulty nonce validation in its AJAX actions function. This vulnerability allows unauthenticated attackers to manipulate image categories by deceiving site administrators into triggering forged requests, such as clicking a malicious link. Proper nonce verification should be implemented to mitigate this risk and prevent unauthorized actions within the plugin.
Affected Version(s)
Mediamatic – Media Library Folders * <= 2.8.1