CVE-2025-28949 - WordPress Mediabay - WordPress Media Library Folders <= 1.4 - sql injection vuln...

CVE-2025-28949 - WordPress Mediabay - WordPress Media Library Folders <= 1.4 - sql injection vuln...

CVE ID : CVE-2025-28949 Published : Dec. 31, 2025, 8:15 p.m. | 55 minutes ago Description : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Dec. 31, 2025
Affected Product: WordPress
Impact: SQL Injection

Source: Telegram CVE Monitor