CVE-2026-94297
Received Received - Intake

Media Library Organizer Taxonomy Term Creation Privilege Escalation

Vulnerability report for CVE-2026-94297, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WPScan

Description

The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
media_library_organizer media_library_organizer to 2.1.4 (exc)
media_library_organizer plugin From 2.0.4 (inc) to 2.1.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Media Library Organizer WordPress plugin versions 2.0.4 to 2.1.3. It allows users with contributor-level access or higher to create taxonomy terms that are publicly visible without proper authorization. The plugin fails to verify if the user has the required capability to manage the target taxonomy before allowing term creation.

Detection Guidance

Check if the Media Library Organizer plugin version is between 2.0.4 and 2.1.3. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the installed version.

Impact Analysis

An attacker with contributor-level access could create unauthorized taxonomy terms, potentially leading to unauthorized content organization or exposure of sensitive data. This could disrupt site functionality or allow manipulation of how content is categorized and displayed.

Compliance Impact

This vulnerability could lead to unauthorized data exposure or manipulation, which may violate compliance requirements for data integrity and access control in standards like GDPR or HIPAA. Unauthorized taxonomy terms might expose sensitive information improperly.

Mitigation Strategies

Update the Media Library Organizer plugin to version 2.1.4 or later immediately. If updating is not possible, consider temporarily disabling the plugin until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94297. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart