Vulnerability Description
The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the import-csv REST API endpoint in all versions up to, and including, 2.3.1. This is due to the endpoint using `upload_files` capability check (Author level) for a destructive operation that can delete all folders. This makes it possible for authenticated attackers, with Author-level access and above, to delete all folder organization data created by Administrators and other users.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/mediacommander/trunk/includes/Models/
- https://plugins.trac.wordpress.org/browser/mediacommander/trunk/includes/Rest/Co
- https://plugins.trac.wordpress.org/changeset/3417928/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9102fe7e-7baa-4bc0-879
FAQ
What is CVE-2025-14508?
CVE-2025-14508 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the import-csv REST API endpoint in ...
How severe is CVE-2025-14508?
CVE-2025-14508 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14508?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.