Impact
The Media Library Organizer plugin fails to verify that a user holds the required capability to manage a taxonomy before creating a new term, allowing anyone with contributor-level access or higher to add publicly visible taxonomy terms. This flaw permits unauthorized data creation and bypasses the site’s intended authority controls, potentially affecting content visibility and navigation.
Affected Systems
WordPress sites that have the Media Library Organizer plugin version 2.0.4 up to and including 2.1.3 are vulnerable. Any user with a contributor or higher role who has access to the site’s admin interface can exploit the issue regardless of the vendor, as the product name is "Media Library Organizer".
Risk and Exploitability
Because no EPSS score or KEV listing exists, the precise exploitation probability cannot be quantified, but the lack of a capability check presents a clear authorization bypass. The vulnerability can be triggered by any authenticated contributor, and resulting terms are immediately visible site‑wide. While no public exploit is documented, the ability to inject arbitrary taxonomy labels could be used to mislead visitors, affect search outcomes, or facilitate spam. Upgrading to version 2.1.4, which reinstates proper capability verification, eliminates the flaw.
OpenCVE Enrichment