HomeWordPress vulnerabilitiesMedia Library Assistant
Media Library Assistant vulnerabilities
Media Library Assistant has 26 known vulnerabilities in this database. The most recent published record is dated 7 Oct 2026.
- Known vulnerabilities
- 26
- Active installs
- 70,000+
- Latest version
- 3.42
- Last updated
- 27 Sep 2026
- Most recent
- 7 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-97294 | Medium 6.5 | Up to 3.41 | Fixed in a later version (latest 3.42) | 15 h ago |
| Cross-site scripting (XSS) CVE-2026-6642 | Medium 6.4 | Up to 3.35 | Fixed in a later version (latest 3.42) | 11 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-6641 | Medium 6.4 | Up to 3.35 | Fixed in a later version (latest 3.42) | 11 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-6640 | Medium 6.4 | Up to 3.35 | Fixed in a later version (latest 3.42) | 11 Sep 2026 |
| SQL injection CVE-2026-16959 | Medium 6.8 | Before 3.40 | Fixed in 3.40 | 21 Aug 2026 |
| Cross-site request forgery (CSRF) CVE-2026-6075 | High 8.1 | Up to 3.35 | Fixed in a later version (latest 3.42) | 29 May 2026 |
| Broken access control CVE-2026-3072 | Medium 4.3 | Up to 3.33 | Fixed in a later version (latest 3.42) | 5 Mar 2026 |
| Arbitrary file deletion CVE-2025-11738 | Medium 5.3 | Up to 3.29 | Fixed in a later version (latest 3.42) | 18 Oct 2025 |
| Arbitrary file deletion CVE-2025-8357 | Medium 4.3 | Up to 3.27 | Fixed in a later version (latest 3.42) | 19 Aug 2025 |
| Cross-site scripting (XSS) CVE-2025-7035 | Medium 6.4 | Before 3.27 | Fixed in 3.27 | 16 Jul 2025 |
| Cross-site scripting (XSS) CVE-2024-11974 | Medium 6.1 | Up to 3.23 | Fixed in a later version (latest 3.42) | 4 Jan 2025 |
| Remote code execution CVE-2024-6823 | High 8.8 | Before 3.19 | Fixed in 3.19 | 13 Aug 2024 |
| Cross-site scripting (XSS) CVE-2024-5544 | Medium 6.1 | Before 3.18 | Fixed in 3.18 | 2 Jul 2024 |
| SQL injection CVE-2024-5605 | High 8.8 | Before 3.17 | Fixed in 3.17 | 20 Jun 2024 |
| SQL injection CVE-2024-3518 | High 8.8 | Before 3.16 | Fixed in 3.16 | 22 May 2024 |
| Cross-site scripting (XSS) CVE-2024-3519 | Medium 6.1 | Before 3.16 | Fixed in 3.16 | 22 May 2024 |
| SQL injection CVE-2024-2871 | Medium 6.4 | Before 3.14 | Fixed in 3.14 | 9 Apr 2024 |
| Cross-site scripting (XSS) CVE-2024-2475 | Medium 6.4 | Before 3.14 | Fixed in 3.14 | 29 Mar 2024 |
| Cross-site scripting (XSS) CVE-2023-4716 | Medium 6.4 | Up to 3.10 | Fixed in a later version (latest 3.42) | 22 Sep 2023 |
| Remote code execution CVE-2023-4634 | Critical 9.8 | Before 3.10 | Fixed in 3.10 | 6 Sep 2023 |
| SQL injection CVE-2023-0279 | High 7.2 | Before 3.06 | Fixed in 3.06 | 27 Feb 2023 |
| Sensitive data exposure CVE-2022-41618 | Low 3.7 | Before 3.01 | Fixed in 3.01 | 18 Nov 2022 |
| Remote code execution CVE-2020-11928 | Critical 9.8 | Before 2.82 | Fixed in 2.82 | 20 Apr 2020 |
| Cross-site scripting (XSS) CVE-2020-11731 | Medium 6.1 | Before 2.82 | Fixed in 2.82 | 13 Apr 2020 |
| File inclusion CVE-2020-11732 | High 7.5 | Before 2.82 | Fixed in 2.82 | 13 Apr 2020 |
| Cross-site scripting (XSS) CVE-2018-20982 | Medium 6.1 | Before 2.74 | Fixed in 2.74 | 22 Aug 2019 |
Read the published descriptions
- CVE-2026-97294, 7 Oct 2026
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41. CVE record
- CVE-2026-6642, 11 Sep 2026
- The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the mla_generate_bulk_edit_form_fieldsets() function and mla-bulk-edit-fieldsets.tpl template. While wp_kses() filtering is applied during preset export for users without unfiltered_html capability, this does not prevent attribute injection attacks since the malicious payload consists of quotes and HTML attributes rather than HTML tags. When preset values are retrieved and rendered, they are directly assigned to template variables without esc_attr() escaping and then inserted into input element value attributes via simple string replacement. This makes it possible for authenticated attackers, with Author-level access and above (upload_files capability), to inject arbitrary web scripts that execute when an administrator imports the poisoned preset and the targeted input field receives focus. CVE record
- CVE-2026-6641, 11 Sep 2026
- The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the _paginate_links() function processes the value through mla_process_shortcode_parameter() and _replace_query_parameter() without proper URL escaping, then outputs it directly in href attributes without applying esc_url(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-6640, 11 Sep 2026
- The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-16959, 21 Aug 2026
- The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection. CVE record
- CVE-2026-6075, 29 May 2026
- The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into performing bulk delete, edit, or purge operations on plugin settings and attachment metadata via a forged request. CVE record
- CVE-2026-3072, 5 Mar 2026
- The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify taxonomy terms on arbitrary attachments. CVE record
- CVE-2025-11738, 18 Oct 2025
- The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive information. CVE record
- CVE-2025-8357, 19 Aug 2025
- The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user capability checking in the _process_mla_download_file function in all versions up to, and including, 3.27. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server from the /wp-content/uploads/ directory. CVE record
- CVE-2025-7035, 16 Jul 2025
- The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-11974, 4 Jan 2025
- The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2024-6823, 13 Aug 2024
- The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
- CVE-2024-5544, 2 Jul 2024
- The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2024-5605, 20 Jun 2024
- The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2024-3518, 22 May 2024
- The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2024-3519, 22 May 2024
- The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter in all versions up to, and including, 3.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2024-2871, 9 Apr 2024
- The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2024-2475, 29 Mar 2024
- The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-4716, 22 Sep 2023
- The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to, and including, 3.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-4634, 6 Sep 2023
- The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible. CVE record
- CVE-2023-0279, 27 Feb 2023
- The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. CVE record
- CVE-2022-41618, 18 Nov 2022
- Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress. CVE record
- CVE-2020-11928, 20 Apr 2020
- In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin. CVE record
- CVE-2020-11731, 13 Apr 2020
- The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/Media Library Assistant tabs, which allow remote authenticated users to execute arbitrary JavaScript. CVE record
- CVE-2020-11732, 13 Apr 2020
- The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download. CVE record
- CVE-2018-20982, 22 Aug 2019
- The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens. CVE record
What to do if you run Media Library Assistant
If you run Media Library Assistant, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Media Library Assistant vulnerabilities
Free. We email you when a new vulnerability is published for Media Library Assistant, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.