Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesMedia Library Assistant

Media Library Assistant vulnerabilities

Media Library Assistant has 26 known vulnerabilities in this database. The most recent published record is dated 7 Oct 2026.

Known vulnerabilities
26
Active installs
70,000+
Latest version
3.42
Last updated
27 Sep 2026
Most recent
7 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-97294
Medium 6.5Up to 3.41Fixed in a later version (latest 3.42)15 h ago
Cross-site scripting (XSS)
CVE-2026-6642
Medium 6.4Up to 3.35Fixed in a later version (latest 3.42)11 Sep 2026
Cross-site scripting (XSS)
CVE-2026-6641
Medium 6.4Up to 3.35Fixed in a later version (latest 3.42)11 Sep 2026
Cross-site scripting (XSS)
CVE-2026-6640
Medium 6.4Up to 3.35Fixed in a later version (latest 3.42)11 Sep 2026
SQL injection
CVE-2026-16959
Medium 6.8Before 3.40Fixed in 3.4021 Aug 2026
Cross-site request forgery (CSRF)
CVE-2026-6075
High 8.1Up to 3.35Fixed in a later version (latest 3.42)29 May 2026
Broken access control
CVE-2026-3072
Medium 4.3Up to 3.33Fixed in a later version (latest 3.42)5 Mar 2026
Arbitrary file deletion
CVE-2025-11738
Medium 5.3Up to 3.29Fixed in a later version (latest 3.42)18 Oct 2025
Arbitrary file deletion
CVE-2025-8357
Medium 4.3Up to 3.27Fixed in a later version (latest 3.42)19 Aug 2025
Cross-site scripting (XSS)
CVE-2025-7035
Medium 6.4Before 3.27Fixed in 3.2716 Jul 2025
Cross-site scripting (XSS)
CVE-2024-11974
Medium 6.1Up to 3.23Fixed in a later version (latest 3.42)4 Jan 2025
Remote code execution
CVE-2024-6823
High 8.8Before 3.19Fixed in 3.1913 Aug 2024
Cross-site scripting (XSS)
CVE-2024-5544
Medium 6.1Before 3.18Fixed in 3.182 Jul 2024
SQL injection
CVE-2024-5605
High 8.8Before 3.17Fixed in 3.1720 Jun 2024
SQL injection
CVE-2024-3518
High 8.8Before 3.16Fixed in 3.1622 May 2024
Cross-site scripting (XSS)
CVE-2024-3519
Medium 6.1Before 3.16Fixed in 3.1622 May 2024
SQL injection
CVE-2024-2871
Medium 6.4Before 3.14Fixed in 3.149 Apr 2024
Cross-site scripting (XSS)
CVE-2024-2475
Medium 6.4Before 3.14Fixed in 3.1429 Mar 2024
Cross-site scripting (XSS)
CVE-2023-4716
Medium 6.4Up to 3.10Fixed in a later version (latest 3.42)22 Sep 2023
Remote code execution
CVE-2023-4634
Critical 9.8Before 3.10Fixed in 3.106 Sep 2023
SQL injection
CVE-2023-0279
High 7.2Before 3.06Fixed in 3.0627 Feb 2023
Sensitive data exposure
CVE-2022-41618
Low 3.7Before 3.01Fixed in 3.0118 Nov 2022
Remote code execution
CVE-2020-11928
Critical 9.8Before 2.82Fixed in 2.8220 Apr 2020
Cross-site scripting (XSS)
CVE-2020-11731
Medium 6.1Before 2.82Fixed in 2.8213 Apr 2020
File inclusion
CVE-2020-11732
High 7.5Before 2.82Fixed in 2.8213 Apr 2020
Cross-site scripting (XSS)
CVE-2018-20982
Medium 6.1Before 2.74Fixed in 2.7422 Aug 2019
Read the published descriptions
CVE-2026-97294, 7 Oct 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41. CVE record
CVE-2026-6642, 11 Sep 2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the mla_generate_bulk_edit_form_fieldsets() function and mla-bulk-edit-fieldsets.tpl template. While wp_kses() filtering is applied during preset export for users without unfiltered_html capability, this does not prevent attribute injection attacks since the malicious payload consists of quotes and HTML attributes rather than HTML tags. When preset values are retrieved and rendered, they are directly assigned to template variables without esc_attr() escaping and then inserted into input element value attributes via simple string replacement. This makes it possible for authenticated attackers, with Author-level access and above (upload_files capability), to inject arbitrary web scripts that execute when an administrator imports the poisoned preset and the targeted input field receives focus. CVE record
CVE-2026-6641, 11 Sep 2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the _paginate_links() function processes the value through mla_process_shortcode_parameter() and _replace_query_parameter() without proper URL escaping, then outputs it directly in href attributes without applying esc_url(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-6640, 11 Sep 2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-16959, 21 Aug 2026
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection. CVE record
CVE-2026-6075, 29 May 2026
The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into performing bulk delete, edit, or purge operations on plugin settings and attachment metadata via a forged request. CVE record
CVE-2026-3072, 5 Mar 2026
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify taxonomy terms on arbitrary attachments. CVE record
CVE-2025-11738, 18 Oct 2025
The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive information. CVE record
CVE-2025-8357, 19 Aug 2025
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user capability checking in the _process_mla_download_file function in all versions up to, and including, 3.27. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server from the /wp-content/uploads/ directory. CVE record
CVE-2025-7035, 16 Jul 2025
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-11974, 4 Jan 2025
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2024-6823, 13 Aug 2024
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
CVE-2024-5544, 2 Jul 2024
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2024-5605, 20 Jun 2024
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-3518, 22 May 2024
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-3519, 22 May 2024
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter in all versions up to, and including, 3.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2024-2871, 9 Apr 2024
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-2475, 29 Mar 2024
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-4716, 22 Sep 2023
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to, and including, 3.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-4634, 6 Sep 2023
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible. CVE record
CVE-2023-0279, 27 Feb 2023
The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. CVE record
CVE-2022-41618, 18 Nov 2022
Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress. CVE record
CVE-2020-11928, 20 Apr 2020
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin. CVE record
CVE-2020-11731, 13 Apr 2020
The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/Media Library Assistant tabs, which allow remote authenticated users to execute arbitrary JavaScript. CVE record
CVE-2020-11732, 13 Apr 2020
The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download. CVE record
CVE-2018-20982, 22 Aug 2019
The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens. CVE record

What to do if you run Media Library Assistant

If you run Media Library Assistant, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Media Library Assistant vulnerabilities

Free. We email you when a new vulnerability is published for Media Library Assistant, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support