« Volver al listado

Media Library Assistant

Media Library Assistant: vulnerabilidades y CVE

Media Library Assistant tiene 13 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses12
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97293Alta (8.5)0.25%—30 sept 2026
Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
CVE-2026-6642Media (6.4)0.36%—11 sept 2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output…
CVE-2026-6641Media (6.4)0.36%—11 sept 2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and…
CVE-2026-6640Media (6.4)0.42%—11 sept 2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and…
CVE-2026-16959Media (6.8)0.39%—21 ago 2026
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to…
CVE-2026-66601Media (6.5)0.22%—20 ago 2026
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66600Crítica (9.1)0.50%—20 ago 2026
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-61963Alta (7.1)0.25%—6 ago 2026
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
CVE-2026-54198Alta (7.1)0.25%—16 jun 2026
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
CVE-2026-6075Alta (8.1)0.32%—29 may 2026
The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings…
CVE-2026-3072Media (4.3)0.35%—5 mar 2026
The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and…
CVE-2025-11738Media (5.3)0.41%—18 oct 2025
The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers…
CVE-2025-8357Media (4.3)0.32%—19 ago 2025
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user capability checking in the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript2
  2. T1189 Drive-by Compromise2
  3. T1210 Exploitation of Remote Services2
  4. T1005 Data from Local System1
  5. T1203 Exploitation for Client Execution1
  6. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.