Description
The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due to a missing capability check on the url_media_uploader_url_upload_ajax_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload safe media files.
Problem types
Product status
* (semver)
Timeline
| 2025-12-11: | Disclosed |
Credits
jason carle
References
gist.github.com/jasoncarle/925401bb11833b1ced2342390e20718e
www.wordfence.com/...-0d2c-45db-b3ed-19a7c9f5a001?source=cve
plugins.trac.wordpress.org/...r/trunk/url-media-uploader.php
gist.github.com/jasoncarle/925401bb11833b1ced2342390e20718e
plugins.trac.wordpress.org/...s/1.0.1/url-media-uploader.php
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.