Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wp_media — Vulnerabilities & Security Advisories 7

Browse all 7 CVE security advisories affecting wp_media. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wp_media is a WordPress plugin designed for media file management and optimization. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The plugin's handling of file uploads and insufficient input sanitization have frequently led to security incidents. With six CVEs recorded, wp_media has faced recurring problems related to improper access controls and insufficient validation of user-supplied data. Security researchers have identified multiple instances where unauthenticated attackers could exploit these vulnerabilities to compromise affected websites, highlighting the importance of regular updates and proper security hardening for this plugin.

CVE ID Title CVSS Severity Published
CVE-2026-100196 LazyLoad Plugin <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content — LazyLoad Plugin – Lazy Load Images, Videos, and Iframes CWE-79 7.2 High 2026-10-10
CVE-2026-6227 BackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter — BackWPup – WordPress Backup & Restore Plugin CWE-22 7.2 High 2026-04-14
CVE-2025-15041 BackWPup <= 5.6.2 - Authenticated (BackWPup Helper+) Privilege Escalation via Arbitrary Options Update — BackWPup – WordPress Backup & Restore Plugin CWE-862 7.2 High 2026-02-19
CVE-2025-10579 BackWPup <= 5.5.0 - Missing Authorization to Sensitive Information Exposure — BackWPup – WordPress Backup & Restore Plugin CWE-862 5.3 Medium 2025-10-25
CVE-2023-5505 BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal — BackWPup – WordPress Backup & Restore Plugin CWE-22 6.8 Medium 2024-08-17
CVE-2023-5775 BackWPup <= 4.0.2 - Plaintext Storage of Backup Destination Password — BackWPup – WordPress Backup & Restore Plugin CWE-256 2.2 Low 2024-02-24
CVE-2023-5504 BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal — BackWPup – WordPress Backup & Restore Plugin CWE-22 8.7 High 2024-01-11

This page lists every published CVE security advisory associated with wp_media. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.