CVE-2026-94297 Overview
CVE-2026-94297 is a broken access control vulnerability in the Media Library Organizer WordPress plugin before version 2.1.4. The plugin fails to verify that the requesting user holds the target taxonomy's management capability before creating a new term. Authenticated users with contributor-level access or above can create publicly visible terms in any taxonomy registered on the site. The flaw affects site content organization and can result in unauthorized taxonomy pollution across categories, tags, and custom taxonomies registered by other plugins or themes.
Critical Impact
Contributor-level accounts can create arbitrary public terms across any registered taxonomy, bypassing the intended capability model of WordPress.
Affected Products
- Media Library Organizer WordPress plugin versions prior to 2.1.4
- WordPress sites permitting contributor-level user registration
- Sites using custom taxonomies registered by third-party plugins or themes
Discovery Timeline
- 2026-09-30 - CVE-2026-94297 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-94297
Vulnerability Analysis
The vulnerability is a missing authorization check [CWE-862] in the term creation handler exposed by the Media Library Organizer plugin. WordPress taxonomies each declare a capabilities map that includes manage_terms, edit_terms, delete_terms, and assign_terms. Standard practice requires plugin code to call current_user_can() against the taxonomy's manage_terms capability before invoking wp_insert_term(). The affected plugin omits this check on its term creation endpoint. Any authenticated user whose role permits access to the plugin's interface, including contributors, can submit a request that inserts a new term into any taxonomy registered on the site.
Root Cause
The root cause is broken access control in the plugin's AJAX or admin request handler that processes term creation. The handler validates only that the request originates from an authenticated user, without matching the caller's capabilities to the taxonomy being modified. As a result, capability separation between roles such as contributor, author, editor, and administrator is not enforced for term insertion operations exposed through the plugin.
Attack Vector
An authenticated attacker with at least contributor privileges sends a crafted request to the plugin's term creation endpoint, specifying an arbitrary taxonomy name and term value. The plugin invokes the term creation function without a capability check, and the term appears publicly on the site. Attackers can use this to inject spam, SEO poisoning content, or misleading navigation entries, or to pollute taxonomies belonging to unrelated plugins such as WooCommerce product categories. See the WPScan Vulnerability Report for reproduction details.
Detection Methods for CVE-2026-94297
Indicators of Compromise
- Unexpected new terms in wp_terms and wp_term_taxonomy tables created by low-privilege accounts.
- Public taxonomy archives containing spam, promotional text, or SEO keyword strings unrelated to site content.
- Audit log entries showing contributor accounts triggering the plugin's term creation endpoint.
Detection Strategies
- Query the database for terms created by users whose role should not include manage_categories or equivalent taxonomy capabilities.
- Review web server access logs for POST requests to the plugin's AJAX action handlers originating from contributor sessions.
- Compare current taxonomy contents against a known-good baseline to identify unauthorized additions.
Monitoring Recommendations
- Enable a WordPress audit logging plugin that records term creation events with the acting user ID.
- Alert on term creation activity from any account that lacks the manage_categories capability.
- Monitor for large-volume term insertions in short time windows, which indicate automated abuse.
How to Mitigate CVE-2026-94297
Immediate Actions Required
- Upgrade the Media Library Organizer plugin to version 2.1.4 or later on all WordPress sites.
- Audit existing taxonomy contents and remove terms created by unauthorized users.
- Review the roles assigned to registered users and reduce privileges where contributor access is not required.
Patch Information
The vendor addressed CVE-2026-94297 in Media Library Organizer version 2.1.4. The fix adds a capability check that verifies the requesting user holds the target taxonomy's manage_terms capability before creating a new term. Site operators should apply the update through the WordPress plugin manager or by replacing plugin files with the patched release. Reference the WPScan Vulnerability Report for advisory details.
Workarounds
- Disable the Media Library Organizer plugin until the patched version can be deployed.
- Restrict contributor-level user registration on affected sites and require administrator approval for new accounts.
- Place the plugin's admin endpoints behind a web application firewall rule that blocks requests from users without the manage_categories capability.
# Update Media Library Organizer using WP-CLI
wp plugin update media-library-organizer --version=2.1.4
# Verify installed version
wp plugin get media-library-organizer --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
