CVE-2025-28948

All FrameworksWordPressCWE-352CVE-2025-28948

CVE-2025-28948

State: PUBLISHED · Published: 2025-06-06 · Updated: 2025-06-06 · Assigner: Patchstack
Description
Cross-Site Request Forgery (CSRF) vulnerability in codedraft Mediabay - WordPress Media Library Folders allows Reflected XSS. This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/28xxx/CVE-2025-28948.json