
WP Media File Type Manager Security & Risk Analysis
wordpress.org/plugins/wp-media-file-type-managerWP Media File Type Manager will allow you to manage different file types in Media Library.
Is WP Media File Type Manager Safe to Use in 2026?
Mostly Safe
Score 78/100WP Media File Type Manager is generally safe to use. 1 past CVE were resolved. Keep it updated.
The wp-media-file-type-manager plugin v2.3.1 exhibits a mixed security posture. While the attack surface appears minimal with no identified AJAX handlers, REST API routes, shortcodes, or cron events, several concerning code signals raise red flags. The single SQL query is not using prepared statements, and a significant portion of output is not properly escaped, indicating potential vulnerabilities related to data injection or cross-site scripting. The taint analysis revealing unsanitized paths, even if not classified as critical or high, suggests a risk of improper handling of user-supplied data that could lead to unintended file system operations or information disclosure.
The plugin's vulnerability history is also a significant concern. The presence of a known, currently unpatched medium severity CVE suggests a persistent security weakness. The fact that the last vulnerability was reported in the future (2025-06-05) is highly anomalous and likely an error in the data, but the existence of a medium severity CVE that remains unpatched is a clear indicator of an ongoing risk. Coupled with the absence of nonce and capability checks, this plugin presents a notable risk that requires attention and remediation.
In conclusion, despite a seemingly small attack surface, the raw SQL query, poor output escaping, potential taint issues, and a known unpatched vulnerability point to significant security weaknesses. Users of this plugin should exercise extreme caution until these issues are addressed. The reported future vulnerability date is a data anomaly that should be investigated, but the unpatched medium CVE is a concrete and present danger.
Key Concerns
- Unpatched medium severity CVE
- SQL queries not using prepared statements
- Significant portion of output not properly escaped
- Flows with unsanitized paths
- No nonce checks
- No capability checks
- Bundled library (DataTables)
WP Media File Type Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Media File Type Manager <= 2.3.0 - Cross-Site Request Forgery to Settings Update
WP Media File Type Manager Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Media File Type Manager Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Media File Type Manager Maintenance & Trust
Maintenance Signals
Community Trust
WP Media File Type Manager Alternatives
Safe SVG
safe-svg
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
FileBird – WordPress Media Library Folders & File Manager
filebird
Organize thousands of WordPress media files in folders / categories with ease.
Real Media Library: Media Library Folder & File Manager
real-media-library-lite
Organize uploaded media in folders, collections and galleries: A file manager for WordPress. Media management made easy with Real Media Library! (Alte …
EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time
wp-maximum-upload-file-size
EasyMedia - Increase the maximum upload file size limit to any value. Increase upload limit - upload large files effortlessly.
WP Extra File Types
wp-extra-file-types
Plugin to let you extend the list of allowed file types supported by the Wordpress Media Library
WP Media File Type Manager Developer Profile
4 plugins · 1K total installs
How We Detect WP Media File Type Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-media-file-type-manager/assets/css/admin.css/wp-content/plugins/wp-media-file-type-manager/assets/css/jquery.dataTables.min.css/wp-content/plugins/wp-media-file-type-manager/assets/js/admin.js/wp-content/plugins/wp-media-file-type-manager/assets/js/jquery.dataTables.min.js/wp-content/plugins/wp-media-file-type-manager/assets/js/admin.js/wp-content/plugins/wp-media-file-type-manager/assets/js/jquery.dataTables.min.jsHTML / DOM Fingerprints
file_extensionfile_typewpmftm-managername="file_extension"name="file_type"name="mft_post_id"name="wpmftm_save_file_type"name="action"name="wpmf_type_id[]"