---
id: CVE-2026-94297
title: >-
  The Media Library Organizer  WordPress plugin before 2.1.4 does not verify
  that the requesting user holds the target taxonomy's management capability
  before creating a new term, allowing users with contributor-level access and
  above to c…
summary: >-
  The Media Library Organizer  WordPress plugin before 2.1.4 does not verify
  that the requesting user holds the target taxonomy's management capability
  before creating a new term, allowing users with contributor-level access and
  above to c…
severity: none
cwe:
  - CWE-862
product: Media Library Organizer
affected:
  - media_library_organizer >= 2.0.4 < 2.1.4
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:10.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94297'
references:
  - url: 'https://wpscan.com/vulnerability/c9cecfb4-d554-4d64-8d87-9678363d8b8d/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.559Z'
---

## Overview

The Media Library Organizer  WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
