Executive brief
A security vulnerability exists in the WP Media folder Addon, a WordPress plugin used for advanced media management. An unauthenticated attacker can download sensitive files from the web server, potentially exposing configuration files, database credentials, or site backups. This could lead to a full site takeover or the theft of customer data.
Technical details
A path traversal vulnerability (CWE-22) exists in the Joomunited WP Media folder Addon plugin for WordPress. The flaw allows an unauthenticated remote attacker to perform arbitrary file downloads by sending specially crafted requests to the server. Because the application fails to properly validate or sanitize user-supplied input used to identify files for download, an attacker can access files outside of the intended directory, such as wp-config.php. This vulnerability is resolved in version 4.0.2.
Affected products
- Joomunited WP Media folder Addon <= 4.0.1
Timeline
- 2025-10-22: other: Vulnerability reported by researcher 0xd4rk5id3
- 2026-06-04: advisory: Patchstack published advisory and mitigation rules
- 2026-06-17: disclosed: CVE published to NVD