Executive brief
The Media Sync plugin for WordPress, which helps site administrators synchronize files between their server and the WordPress Media Library, contains a security flaw. This vulnerability allows logged-in users with Author-level permissions or higher to access or manipulate files outside of the designated media folder. This could lead to the exposure of sensitive system files or unauthorized changes to the website's file structure.
Technical details
The Media Sync plugin for WordPress is vulnerable to path traversal (CWE-22) due to insufficient validation of user-supplied file paths in the 'sub_dir' and 'media_items' parameters. The application fails to sanitize directory traversal sequences (e.g., '../') or verify that the requested paths are restricted to the intended uploads directory. An authenticated attacker with Author-level privileges or higher can exploit this to interact with files outside of the web root or intended media folders. A patch has been identified in the plugin's changeset 3511221.
Affected products
- Erol Hasanovic Media Sync up to, and including, 1.4.9
Timeline
- 2026-05-14: advisory: NVD published the CVE record based on Wordfence data.
- 2026-05-14: disclosed