Junglewise Threat Intelligence

CVE-2026-11974: JoomUnited wp-media-folder-addon Arbitrary File Disclosure and SSRF

CVE-2026-11974 · Severity: info · CVSS 8.6 · Published 2026-07-29

Vendors: JoomUnited.

Executive brief

The wp-media-folder-addon plugin for WordPress, which extends media management capabilities with cloud storage integration, contains a security flaw that allows unauthorized users to access sensitive files. By exploiting this vulnerability, an attacker can read internal system files or perform unauthorized requests to other internal services, potentially leading to data theft or further network compromise. This issue exists because a previous security fix was incomplete, leaving several cloud storage handlers unprotected.

Technical details

The wp-media-folder-addon plugin fails to validate user-supplied parameters before using them in file read operations within two specific AJAX actions. This vulnerability is accessible to unauthenticated remote attackers and can lead to Arbitrary File Disclosure and Server-Side Request Forgery (SSRF), particularly on installations where cloud storage connections (such as Google Drive or Dropbox) are configured. This vulnerability stems from an incomplete fix for a previous issue (CVE-2026-9690), where only one cloud-storage handler was hardened while others remained vulnerable. As of the advisory date, no known fix has been released for version 4.1.6.

Affected products

  • JoomUnited wp-media-folder-addon <= 4.1.6

Timeline

  • 2026-07-08: disclosed: Initial public disclosure by WPScan
  • 2026-07-29: advisory: NVD publication date

References

Related threats