Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4.
Published: 2025-12-31
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an improper neutralization of special elements used in an SQL command, allowing attackers to perform blind SQL injection against the WordPress Mediabay - WordPress Media Library Folders plugin. When successfully exploited, an attacker can read, modify, or delete database contents through carefully crafted queries, potentially undermining confidentiality, integrity, and availability. The weakness is categorized as CWE‑89, a classic input validation flaw that undermines database access controls.

Affected Systems

Any WordPress site that has installed the Mediabay – WordPress Media Library Folders plugin, from the earliest released version through 1.4. The vulnerability is present in all plugin versions up to and including 1.4; later releases are not affected according to the vendor’s affected-version details.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity. The EPSS score of less than 1% suggests a low current probability of exploitation, and the issue is not listed in the CISA KEV catalog, reducing near-term public threat concerns. However, because the vulnerability allows blind data extraction through the web interface, any site that exposes the plugin’s input fields to authenticated or unauthenticated users could be exploited when the attacker has network connectivity to the application. The attack vector is inferred to be via web requests to the plugin’s endpoints, without needing additional system access.

Generated by OpenCVE AI on May 1, 2026 at 06:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mediabay – WordPress Media Library Folders to the latest version (1.5 or later).
  • If an upgrade is not available, configure the plugin to sanitize all database input parameters using prepared statements or parameterized queries.
  • Deploy a web application firewall rule set to block or rate‑limit suspicious SQL‑like payloads targeting the plugin’s input fields.

Generated by OpenCVE AI on May 1, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 19:30:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders mediabay allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through <= 1.4. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders mediabay allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through <= 1.4.
References

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Codedraft
Codedraft mediabay - Wordpress Media Library Folders
Wordpress
Wordpress wordpress
Vendors & Products Codedraft
Codedraft mediabay - Wordpress Media Library Folders
Wordpress
Wordpress wordpress

Fri, 02 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4.
Title WordPress Mediabay - WordPress Media Library Folders <= 1.4 - SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Codedraft Mediabay - Wordpress Media Library Folders
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:51.525Z

Reserved: 2025-03-11T08:10:12.306Z

Link: CVE-2025-28949

cve-icon Vulnrichment

Updated: 2026-01-02T19:29:08.471Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T20:15:42.060

Modified: 2026-04-28T19:30:09.430

Link: CVE-2025-28949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T06:15:10Z

Weaknesses