Unauthorized Data Deletion Vulnerability in MediaCommander Plugin for WordPress
CVE-2025-14508
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 December 2025
What is CVE-2025-14508?
The MediaCommander plugin for WordPress, which facilitates folder management in media, posts, and pages, is vulnerable to unauthorized data deletion. This issue arises from a lack of proper capability checks on the import-csv REST API endpoint, present in all versions up to and including 2.3.1. The endpoint dangerously utilizes an upload_files capability check, which only requires Author-level access to execute destructive operations, allowing authenticated attackers with Author roles or higher to delete all folders and their organization data. This vulnerability can lead to significant data loss for Administrators and users managing content.
Affected Version(s)
MediaCommander β Bring Folders to Media, Posts, and Pages * <= 2.3.1