Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

wp_media — Vulnerabilities & Security Advisories 6

Browse all 6 CVE security advisories affecting wp_media. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wp_media is a WordPress plugin designed for media file management and optimization. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The plugin's handling of file uploads and insufficient input sanitization have frequently led to security incidents. With six CVEs recorded, wp_media has faced recurring problems related to improper access controls and insufficient validation of user-supplied data. Security researchers have identified multiple instances where unauthenticated attackers could exploit these vulnerabilities to compromise affected websites, highlighting the importance of regular updates and proper security hardening for this plugin.

CVE IDTitleCVSSSeverityPublished
CVE-2026-6227 BackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter — BackWPup – WordPress Backup & Restore PluginCWE-22 7.2 High2026-04-14
CVE-2025-15041 BackWPup <= 5.6.2 - Authenticated (BackWPup Helper+) Privilege Escalation via Arbitrary Options Update — BackWPup – WordPress Backup & Restore PluginCWE-862 7.2 High2026-02-19
CVE-2025-10579 BackWPup <= 5.5.0 - Missing Authorization to Sensitive Information Exposure — BackWPup – WordPress Backup & Restore PluginCWE-862 5.3 Medium2025-10-25
CVE-2023-5505 BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal — BackWPup – WordPress Backup & Restore PluginCWE-22 6.8 Medium2024-08-17
CVE-2023-5775 BackWPup <= 4.0.2 - Plaintext Storage of Backup Destination Password — BackWPup – WordPress Backup & Restore PluginCWE-256 2.2 Low2024-02-24
CVE-2023-5504 BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal — BackWPup – WordPress Backup & Restore PluginCWE-22 8.7 High2024-01-11

This page lists every published CVE security advisory associated with wp_media. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.