Unauthorized Data Deletion Vulnerability in MediaCommander Plugin for WordPress
CVE-2025-14508
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 December 2025
What is CVE-2025-14508?
The MediaCommander plugin for WordPress, which facilitates folder management in media, posts, and pages, is vulnerable to unauthorized data deletion. This issue arises from a lack of proper capability checks on the import-csv REST API endpoint, present in all versions up to and including 2.3.1. The endpoint dangerously utilizes an upload_files capability check, which only requires Author-level access to execute destructive operations, allowing authenticated attackers with Author roles or higher to delete all folders and their organization data. This vulnerability can lead to significant data loss for Administrators and users managing content.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MediaCommander β Bring Folders to Media, Posts, and Pages * <= 2.3.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved