GI-Media Library < 3.0 - Directory Traversal

CVE Details

Basic Information

Title GI-Media Library < 3.0 - Directory Traversal
Type cve
Published 2025-07-19T09:23:51.606Z
Modified 2025-07-19T09:23:51.606Z

Product Information

Vendor zishanj
Product GI-Media Library
Version *

CVSS Information

Base Score 7.5 (HIGH)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Analysis

AI Description The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal, allowing attackers to read arbitrary files on the server. This could expose sensitive information.
AI Severity High
AI Vendor WordPress Community
AI Product GI-Media Library
AI Version versions before 3.0

Affected Products

  • zishanj GI-Media Library *

Additional Information

CWE List CWE-22
Source Wordfence

Description

The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the ‘fileid’ parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.