Unauthorized Data Deletion Vulnerability in MediaCommander Plugin for WordPress
CVE-2025-14508

6.5MEDIUM

What is CVE-2025-14508?

The MediaCommander plugin for WordPress, which facilitates folder management in media, posts, and pages, is vulnerable to unauthorized data deletion. This issue arises from a lack of proper capability checks on the import-csv REST API endpoint, present in all versions up to and including 2.3.1. The endpoint dangerously utilizes an upload_files capability check, which only requires Author-level access to execute destructive operations, allowing authenticated attackers with Author roles or higher to delete all folders and their organization data. This vulnerability can lead to significant data loss for Administrators and users managing content.

Affected Version(s)

MediaCommander – Bring Folders to Media, Posts, and Pages * <= 2.3.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.
CVE-2025-14508 : Unauthorized Data Deletion Vulnerability in MediaCommander Plugin for WordPress