📦 Media Library Assistant

by Davidlingren

🔍 What is Media Library Assistant?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-51661

CRITICAL CVSS 9.1 Nov 4, 2024

This vulnerability allows remote attackers to execute arbitrary operating system commands on WordPress servers running vulnerable versions of the Media Library Assistant plugin. Attackers can achieve ...

CVE-2023-4634

CRITICAL CVSS 9.8 Sep 6, 2023

The Media Library Assistant WordPress plugin has a critical vulnerability allowing unauthenticated attackers to perform Local File Inclusion and Remote Code Execution. Attackers can exploit insufficie...

CVE-2024-6823

HIGH CVSS 8.8 Aug 13, 2024

The Media Library Assistant WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files due to missing file type validation. This vulnerability affects...

CVE-2024-5605

HIGH CVSS 8.8 Jun 20, 2024

The Media Library Assistant WordPress plugin contains a time-based SQL injection vulnerability in the 'order' parameter of the mla_tag_cloud shortcode. Authenticated attackers with contributor-level a...

CVE-2024-11974

MEDIUM CVSS 6.1 Jan 4, 2025

This vulnerability allows unauthenticated attackers to perform reflected cross-site scripting (XSS) attacks against WordPress sites using the Media Library Assistant plugin. Attackers can inject malic...

CVE-2024-5544

MEDIUM CVSS 6.1 Jul 2, 2024

The Media Library Assistant WordPress plugin has a reflected cross-site scripting vulnerability in all versions up to 3.17. Unauthenticated attackers can inject malicious scripts via the order paramet...

CVE-2024-3519

MEDIUM CVSS 6.1 May 22, 2024

This vulnerability allows unauthenticated attackers to execute reflected cross-site scripting attacks via the lang parameter in the Media Library Assistant WordPress plugin. Attackers can inject malic...