CVE-2025-28949

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Codedraft Mediabay – WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay – WordPress Media Library Folders: from n/a through 1.4.

More information : https://vdp.patchstack.com/database/wordpress/plugin/mediabay/vulnerability/wordpress-mediabay-wordpress-media-library-folders-1-4-sql-injection-vulnerability?_s_id=cve