Media Library Assistant

22 known CVEs 70K+ active installs

Scan My Site Free

UNKNOWN: 22
Known Vulnerabilities 22
CVE-2026-3072 UNKNOWN EPSS 0.1%
Published 2026-03-05 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions
CVE-2025-11738 UNKNOWN EPSS 0.3%
Published 2025-10-18 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthen
CVE-2024-51661 UNKNOWN EPSS 0.6%
Published 2024-11-04 · Affected: *
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This
CVE-2024-51661 UNKNOWN EPSS 0.6%
Published 2024-11-04 · Affected: *
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This
CVE-2024-51661 UNKNOWN EPSS 0.6%
Published 2024-11-04 · Affected: *
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This
CVE-2024-51661 UNKNOWN EPSS 0.6%
Published 2024-11-04 · Affected: *
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This
CVE-2024-5544 UNKNOWN EPSS 0.3%
Published 2024-07-02 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitizati
CVE-2024-5544 UNKNOWN EPSS 0.3%
Published 2024-07-02 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitizati
CVE-2024-5605 UNKNOWN EPSS 0.5%
Published 2024-06-20 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due t
CVE-2024-5605 UNKNOWN EPSS 0.5%
Published 2024-06-20 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due t
CVE-2024-3519 UNKNOWN EPSS 0.3%
Published 2024-05-22 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter in all versions up to, and including, 3.15 due to insufficient input sanitizatio
CVE-2024-3519 UNKNOWN EPSS 0.3%
Published 2024-05-22 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter in all versions up to, and including, 3.15 due to insufficient input sanitizatio
CVE-2024-3518 UNKNOWN EPSS 0.4%
Published 2024-05-22 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.15 due to insufficient escaping on the user suppli
CVE-2024-3518 UNKNOWN EPSS 0.4%
Published 2024-05-22 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.15 due to insufficient escaping on the user suppli
CVE-2024-2871 UNKNOWN EPSS 0.4%
Published 2024-04-09 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user suppli
CVE-2024-2871 UNKNOWN EPSS 0.4%
Published 2024-04-09 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user suppli
CVE-2024-2475 UNKNOWN EPSS 0.4%
Published 2024-03-29 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitizat
CVE-2024-2475 UNKNOWN EPSS 0.4%
Published 2024-03-29 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitizat
CVE-2023-4716 UNKNOWN EPSS 0.4%
Published 2023-09-22 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to, and including, 3.10 due to insufficient input sanitizat
CVE-2023-4716 UNKNOWN EPSS 0.4%
Published 2023-09-22 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to, and including, 3.10 due to insufficient input sanitizat
CVE-2023-4634 UNKNOWN EPSS 1.0%
Published 2023-09-06 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file pa
CVE-2023-4634 UNKNOWN EPSS 1.0%
Published 2023-09-06 · Affected: *
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file pa

Is Media Library Assistant running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free