Media Library Assistant < 3.40 - Authenticated (Author+) SQL Injection
medium
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection in all versions up to 3.40. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and a...
- CVSS:
- 6.5
- Affected:
- up to 3.40
- Fixed in:
- 3.40
- Disclosed:
- Aug 24, 2026
CVE-2026-16959 on NVD →
Media Library Assistant <= 3.39 - Authenticated (Author+) Arbitrary File Upload
high
The Media Library Assistant plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.39. This is due to missing file type validation. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server...
- CVSS:
- 8.8
- Affected:
- up to 3.39
- Fixed in:
- 3.40
- Disclosed:
- Aug 19, 2026
CVE-2026-66600 on NVD →
Media Library Assistant <= 3.39 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.39. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary we...
- CVSS:
- 6.4
- Affected:
- up to 3.39
- Fixed in:
- 3.40
- Disclosed:
- Aug 19, 2026
CVE-2026-66601 on NVD →
Media Library Assistant <= 3.39 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.39. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 3.39
- Fixed in:
- 3.40
- Disclosed:
- Aug 18, 2026
CVE-2026-66591 on NVD →
Media Library Assistant <= 3.38 - Unauthenticated Stored Cross-Site Scripting
high
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.38 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- CVSS:
- 7.2
- Affected:
- up to 3.38
- Fixed in:
- 3.39
- Disclosed:
- Aug 4, 2026
CVE-2026-61963 on NVD →
Media Library Assistant <= 3.35 - Authenticated (Contributor+) SQL Injection
medium
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level acce...
- CVSS:
- 6.5
- Affected:
- up to 3.35
- Fixed in:
- 3.36
- Disclosed:
- Jun 18, 2026
CVE-2026-56012 on NVD →
Media Library Assistant <= 3.35 - Reflected Cross-Site Scripting
medium
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 3.35
- Fixed in:
- 3.36
- Disclosed:
- Jun 15, 2026
CVE-2026-54198 on NVD →
Media Library Assistant <= 3.35 - Cross-Site Request Forgery via Bulk Action Form
high
The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into perf...
- CVSS:
- 8.1
- Affected:
- up to 3.35
- Fixed in:
- 3.36
- Disclosed:
- May 28, 2026
CVE-2026-6075 on NVD →
Media Library Assistant <= 3.34 - Authenticated (Contributor+) SQL Injection
medium
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.34 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level acce...
- CVSS:
- 6.5
- Affected:
- up to 3.34
- Fixed in:
- 3.35
- Disclosed:
- Apr 6, 2026
CVE-2026-34885 on NVD →
Media Library Assistant <= 3.34 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 6.4
- Affected:
- up to 3.34
- Fixed in:
- 3.35
- Disclosed:
- Apr 6, 2026
CVE-2026-34897 on NVD →
Media LIbrary Assistant - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification vulnerability
medium
Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification vulnerability
- CVSS:
- 4.3
- Affected:
- up to 3.33
- Fixed in:
- 3.34
- Disclosed:
- Mar 4, 2026
Media Library Assistant <= 3.33 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification
medium
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes it possible for authenticated attackers, with Subscriber-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 3.33
- Fixed in:
- 3.34
- Disclosed:
- Mar 4, 2026
CVE-2026-3072 on NVD →
Media LIbrary Assistant <= 3.32 - Authenticated (Contributor+) SQL Injection
medium
The Media LIbrary Assistant plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level acce...
- CVSS:
- 6.5
- Affected:
- up to 3.32
- Fixed in:
- 3.33
- Disclosed:
- Feb 20, 2026
CVE-2026-32399 on NVD →
Media Library Assistant [media-library-assistant] <= 3.30 (unfixed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media Library Assistant media-library-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Library Assistant: from n/a through <= 3.30.
- Affected:
- up to 3.30
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-63065 on NVD →
Media Library Assistant [media-library-assistant] < 3.30
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive...
- Affected:
- up to 3.30
- Fixed in:
- 3.30
- Disclosed:
- Oct 18, 2025
CVE-2025-11738 on NVD →
Media Library Assistant <= 3.29 - Unauthenticated Limited File Read
medium
The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive infor...
- CVSS:
- 5.3
- Affected:
- up to 3.29
- Fixed in:
- 3.30
- Disclosed:
- Oct 17, 2025
CVE-2025-11738 on NVD →
Media Library Assistant <= 3.29 - Missing Authorization
medium
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.29. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.29
- Fixed in:
- 3.30
- Disclosed:
- Oct 9, 2025
CVE-2025-63065 on NVD →
Media Library Assistant <= 3.28 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 3.28
- Fixed in:
- 3.29
- Disclosed:
- Sep 22, 2025
CVE-2025-59590 on NVD →
Media Library Assistant <= 3.27 - Authenticated (Author+) Limited File Deletion
medium
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user capability checking in the _process_mla_download_file function in all versions up to, and including, 3.27. This makes it possible for authentic...
- CVSS:
- 4.3
- Affected:
- up to 3.27
- Fixed in:
- 3.28
- Disclosed:
- Aug 18, 2025
CVE-2025-8357 on NVD →
Media Library Assistant <= 3.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes
medium
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...
- CVSS:
- 6.4
- Affected:
- up to 3.26
- Fixed in:
- 3.27
- Disclosed:
- Jul 15, 2025
CVE-2025-7035 on NVD →
Media Library Assistant <= 3.24 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts...
- CVSS:
- 4.4
- Affected:
- up to 3.24
- Fixed in:
- 3.25
- Disclosed:
- Mar 31, 2025
CVE-2025-31627 on NVD →
Media Library Assistant [media-library-assistant] < 3.25
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media Library Assistant allows Stored XSS. This issue affects Media Library Assistant: from n/a through 3.24.
- Affected:
- up to 3.25
- Fixed in:
- 3.25
- Disclosed:
- Mar 31, 2025
CVE-2025-31627 on NVD →
Media Library Assistant [media-library-assistant] < 3.24
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escaping. This makes it possible for una...
- Affected:
- up to 3.24
- Fixed in:
- 3.24
- Disclosed:
- Jan 4, 2025
CVE-2024-11974 on NVD →
Media Library Assistant <= 3.23 - Reflected Cross-Site Scripting via smc_settings_tab, unattachfixit-action, and woofixit-action Parameters
medium
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...
- CVSS:
- 6.1
- Affected:
- up to 3.23
- Fixed in:
- 3.24
- Disclosed:
- Jan 3, 2025
CVE-2024-11974 on NVD →
Media Library Assistant [media-library-assistant] < 3.20
unknown
[en] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media Library Assistant allows Command Injection.This issue affects Media Library Assistant: from n/a through 3.19.
- Affected:
- up to 3.20
- Fixed in:
- 3.20
- Disclosed:
- Nov 4, 2024
CVE-2024-51661 on NVD →
Media Library Assistant <= 3.19 - Authenticated (Administrator+) Remote Code Execution
high
The Media Library Assistant plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.19. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 3.19
- Fixed in:
- 3.20
- Disclosed:
- Nov 1, 2024
CVE-2024-51661 on NVD →
Media Library Assistant [media-library-assistant] < 3.19
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, t...
- Affected:
- up to 3.19
- Fixed in:
- 3.19
- Disclosed:
- Aug 13, 2024
CVE-2024-6823 on NVD →
Media Library Assistant <= 3.18 - Authenticated (Author+) Arbitrary File Upload via mla-inline-edit-upload-scripts AJAX Action
high
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, to upl...
- CVSS:
- 8.8
- Affected:
- up to 3.18
- Fixed in:
- 3.19
- Disclosed:
- Aug 12, 2024
CVE-2024-6823 on NVD →
Media Library Assistant [media-library-assistant] < 3.18
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- Affected:
- up to 3.18
- Fixed in:
- 3.18
- Disclosed:
- Jul 2, 2024
CVE-2024-5544 on NVD →
Media Library Assistant <= 3.17 - Reflected Cross-Site Scripting
medium
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- CVSS:
- 6.1
- Affected:
- up to 3.17
- Fixed in:
- 3.18
- Disclosed:
- Jul 1, 2024
CVE-2024-5544 on NVD →
Media Library Assistant [media-library-assistant] < 3.17
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query...
- Affected:
- up to 3.17
- Fixed in:
- 3.17
- Disclosed:
- Jun 20, 2024
CVE-2024-5605 on NVD →
Media Library Assistant <= 3.16 - Authenticated (Contributor+) SQL Injection via order Parameter
high
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th...
- CVSS:
- 8.8
- Affected:
- up to 3.16
- Fixed in:
- 3.17
- Disclosed:
- Jun 19, 2024
CVE-2024-5605 on NVD →
Media Library Assistant <= 3.15 - Reflected Cross-Site Scripting via lang
medium
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter in all versions up to, and including, 3.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.1
- Affected:
- up to 3.15
- Fixed in:
- 3.16
- Disclosed:
- May 21, 2024
CVE-2024-3519 on NVD →
Media Library Assistant <= 3.15 - Authenticated (Contributor+) SQL Injection via Shortcode
high
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...
- CVSS:
- 8.8
- Affected:
- up to 3.15
- Fixed in:
- 3.16
- Disclosed:
- May 21, 2024
CVE-2024-3518 on NVD →
Media Library Assistant [media-library-assistant] < 3.16
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter in all versions up to, and including, 3.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- Affected:
- up to 3.16
- Fixed in:
- 3.16
- Disclosed:
- May 21, 2024
CVE-2024-3519 on NVD →
Media Library Assistant [media-library-assistant] < 3.16
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...
- Affected:
- up to 3.16
- Fixed in:
- 3.16
- Disclosed:
- May 21, 2024
CVE-2024-3518 on NVD →
Media Library Assistant [media-library-assistant] < 3.14
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticate...
- Affected:
- up to 3.14
- Fixed in:
- 3.14
- Disclosed:
- Apr 9, 2024
CVE-2024-2871 on NVD →
Media Library Assistant [media-library-assistant] < 3.14
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- Affected:
- up to 3.14
- Fixed in:
- 3.14
- Disclosed:
- Mar 29, 2024
CVE-2024-2475 on NVD →
Media Library Assistant <= 3.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_gallery Shortcode
medium
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributo...
- CVSS:
- 6.4
- Affected:
- up to 3.13
- Fixed in:
- 3.14
- Disclosed:
- Mar 28, 2024
CVE-2024-2475 on NVD →
Media Library Assistant <= 3.13 - Authenticated (Contributor+) SQL Injection via Shortcode
medium
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 3.13
- Fixed in:
- 3.14
- Disclosed:
- Mar 25, 2024
CVE-2024-2871 on NVD →
Media Library Assistant [media-library-assistant] < 3.12
unknown
[en] Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in David Lingren Media Library Assistant plugin <= 3.11 versions.
- Affected:
- up to 3.12
- Fixed in:
- 3.12
- Disclosed:
- Oct 17, 2023
CVE-2023-24385 on NVD →
Media Library Assistant <= 3.11 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 3.11
- Fixed in:
- 3.12
- Disclosed:
- Oct 2, 2023
CVE-2023-24385 on NVD →
Media Library Assistant [media-library-assistant] < 3.11
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to, and including, 3.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contri...
- Affected:
- up to 3.11
- Fixed in:
- 3.11
- Disclosed:
- Sep 22, 2023
CVE-2023-4716 on NVD →
Media Library Assistant <= 3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to, and including, 3.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor...
- CVSS:
- 6.4
- Affected:
- up to 3.10
- Fixed in:
- 3.11
- Disclosed:
- Sep 21, 2023
CVE-2023-4716 on NVD →
Media Library Assistant [media-library-assistant] < 3.10
unknown
[en] The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images a...
- Affected:
- up to 3.10
- Fixed in:
- 3.10
- Disclosed:
- Sep 6, 2023
CVE-2023-4634 on NVD →
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
critical
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are pr...
- CVSS:
- 9.8
- Affected:
- up to 3.09
- Fixed in:
- 3.10
- Disclosed:
- Sep 5, 2023
CVE-2023-4634 on NVD →
Media Library Assistant [media-library-assistant] < 3.0.8
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in submodule of David Lingren Media Library Assistant plugin <= 3.0.7 versions.
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Aug 5, 2023
CVE-2023-34010 on NVD →
Media Library Assistant <= 3.07 - Reflected Cross-Site Scripting
medium
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.07 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.8
- Disclosed:
- Jul 12, 2023
CVE-2023-34010 on NVD →
Media Library Assistant [media-library-assistant] < 3.06
unknown
[en] The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
- Affected:
- up to 3.06
- Fixed in:
- 3.06
- Disclosed:
- Feb 27, 2023
CVE-2023-0279 on NVD →
Media Library Assistant <= 3.05 - Authenticated (Administrator+) SQL Injection
high
The Media Library Assistant for WordPress is vulnerable to SQL Injection via the ‘post_types’ parameter in versions up to, and including, 3.05 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for administrator-level attacke...
- CVSS:
- 7.2
- Affected:
- up to 3.05
- Fixed in:
- 3.06
- Disclosed:
- Feb 16, 2023
CVE-2023-0279 on NVD →
Media Library Assistant [media-library-assistant] < 3.01
unknown
[en] Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.
- Affected:
- up to 3.01
- Fixed in:
- 3.01
- Disclosed:
- Nov 18, 2022
CVE-2022-41618 on NVD →
Media Library Assistant <= 3.00 - Information Disclosure
medium
The Media Library Assistant plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.00. This could allow unauthenticated attackers to extract error logs.
- CVSS:
- 5.3
- Affected:
- up to 3.00
- Fixed in:
- 3.01
- Disclosed:
- Sep 29, 2022
CVE-2022-41618 on NVD →
Media Library Assistant [media-library-assistant] < 2.9.0
unknown
Authenticated Blind SQL Injection (SQLi) vulnerability found by Lenon Leite in WordPress Media Library Assistant plugin (versions <= 2.84).
- Affected:
- up to 2.9.0
- Fixed in:
- 2.9.0
- Disclosed:
- Nov 24, 2020
Media Library Assistant [media-library-assistant] < 2.82
unknown
[en] In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
- Affected:
- up to 2.82
- Fixed in:
- 2.82
- Disclosed:
- Apr 19, 2020
CVE-2020-11928 on NVD →
Media Library Assistant [media-library-assistant] < 2.82
unknown
[en] The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.
- Affected:
- up to 2.82
- Fixed in:
- 2.82
- Disclosed:
- Apr 13, 2020
CVE-2020-11732 on NVD →
Media Library Assistant [media-library-assistant] < 2.82
unknown
[en] The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/Media Library Assistant tabs, which allow remote authenticated users to execute arbitrary JavaScript.
- Affected:
- up to 2.82
- Fixed in:
- 2.82
- Disclosed:
- Apr 13, 2020
CVE-2020-11731 on NVD →
Media Library Assistant <= 2.81 - Remote Code Execution via tax_query, meta_query, date_query Parameters
critical
In the Media Library Assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
- CVSS:
- 9.8
- Affected:
- up to 2.81
- Fixed in:
- 2.82
- Disclosed:
- Dec 15, 2019
CVE-2020-11928 on NVD →
Media Library Assistant <= 2.81 - Local File Inclusion
high
The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.
- CVSS:
- 7.5
- Affected:
- up to 2.81
- Fixed in:
- 2.82
- Disclosed:
- Dec 15, 2019
CVE-2020-11732 on NVD →
Media Library Assistant <= 2.81 - Authenticated Cross-Site Scripting
medium
The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/Media Library Assistant tabs, which allow remote authenticated users to execute arbitrary JavaScript.
- CVSS:
- 6.1
- Affected:
- up to 2.82
- Fixed in:
- 2.82
- Disclosed:
- Dec 15, 2019
CVE-2020-11731 on NVD →
Media Library Assistant [media-library-assistant] < 2.74
unknown
[en] The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens.
- Affected:
- up to 2.74
- Fixed in:
- 2.74
- Disclosed:
- Aug 22, 2019
CVE-2018-20982 on NVD →
Media Library Assistant <= 2.73 - Cross-Site Scripting
medium
The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens.
- CVSS:
- 6.1
- Affected:
- up to 2.7.4
- Fixed in:
- 2.74
- Disclosed:
- May 28, 2018
CVE-2018-20982 on NVD →
Media Library Assistant [media-library-assistant] < 3.28
unknown
- Affected:
- up to 3.28
- Fixed in:
- 3.28
CVE-2025-8357 on NVD →
Media Library Assistant [media-library-assistant] < 3.27
unknown
- Affected:
- up to 3.27
- Fixed in:
- 3.27
CVE-2025-7035 on NVD →
Media Library Assistant [media-library-assistant] < 2.90
unknown
The Media Library Assistant WordPress plugin was affected by an authenticated (admin+) blind SQL injection vulnerability when there is at least one Custom Field Rule set in the plugin's options.
- Affected:
- up to 2.90
- Fixed in:
- 2.90