Executive brief
The wp-media-folder-addon plugin for WordPress, which extends media management capabilities with cloud storage integration, contains a security flaw that allows unauthorized users to access sensitive files. By exploiting this vulnerability, an attacker can read internal system files or perform unauthorized requests to other internal services, potentially leading to data theft or further network compromise. This issue exists because a previous security fix was incomplete, leaving several cloud storage handlers unprotected.
Technical details
The wp-media-folder-addon plugin fails to validate user-supplied parameters before using them in file read operations within two specific AJAX actions. This vulnerability is accessible to unauthenticated remote attackers and can lead to Arbitrary File Disclosure and Server-Side Request Forgery (SSRF), particularly on installations where cloud storage connections (such as Google Drive or Dropbox) are configured. This vulnerability stems from an incomplete fix for a previous issue (CVE-2026-9690), where only one cloud-storage handler was hardened while others remained vulnerable. As of the advisory date, no known fix has been released for version 4.1.6.
Affected products
- JoomUnited wp-media-folder-addon <= 4.1.6
Timeline
- 2026-07-08: disclosed: Initial public disclosure by WPScan
- 2026-07-29: advisory: NVD publication date