Junglewise Threat Intelligence

CVE-2025-28949: Codedraft Mediabay SQL injection in WordPress Media Library Folders

CVE-2025-28949 · Severity: high · CVSS 8.5 · Published 2025-12-31

Executive brief

Mediabay is a popular WordPress plugin for organizing media files and creating folder structures in the WordPress Media Library. A SQL injection vulnerability in versions up to 1.4 allows attackers with subscriber-level access to extract, modify, or delete database contents, potentially exposing user accounts and sensitive data stored in WordPress sites.

Technical details

This is a blind SQL injection vulnerability in the Mediabay WordPress plugin affecting versions through 1.4. The vulnerability allows an attacker with subscriber-level privileges to inject arbitrary SQL commands through an unprotected input parameter, enabling them to read, modify, or delete database records. The attack is network-accessible and requires only subscriber credentials—a low-privilege account. No official patch was available as of the advisory date; Patchstack provided a virtual patch/WAF rule as a mitigation measure.

Affected products

  • Codedraft Mediabay through 1.4

Timeline

  • 2025-04-21: disclosed: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
  • 2025-07-15: advisory: Published on Patchstack
  • 2025-12-31: other: Published on NVD

References