WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Media Library Folders

Easier file and folder management for WordPress Media Library for Galleries and Albums

7Reported vulnerabilities
9.9Highest CVSS score
8.3.9Latest version
10,000+Active installs

What to do now

Update Media Library Folders to 8.3.7 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 13, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-30486 Critical 9.9 0.6% 8.1.7 and earlier 8.1.8 March 28, 2024
CVE-2022-41634 High 8.8 0.3% Before 7.1.2 7.1.2 November 18, 2022
CVE-2024-7857 Medium 6.5 0.5% Before 8.2.3 8.2.3 August 29, 2024
CVE-2024-7858 Medium 6.3 0.3% Before 8.2.4 8.2.4 August 30, 2024
CVE-2024-31287 Medium 4.3 0.7% 8.1.8 and earlier 8.1.9 April 5, 2024
CVE-2026-2312 Medium 4.3 0.2% 0 to 8.3.6 (inclusive) 8.3.7 February 14, 2026
CVE-2025-0935 Medium 4.3 0.3% Before 8.3.1 8.3.1 February 15, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.