VulnSea

media_library_assistant vulnerabilities

CVEs whose affected-version data names the media_library_assistant package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-6640Medium· 6.4
1w ago

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. …

Sunlitdglingren · Media Library AssistantEPSS 0.24%via NVD
CVE-2026-6642Medium· 6.4
1w ago

Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset fi…

Sunlitdglingren · Media Library AssistantEPSS 0.22%via CVEORG
CVE-2026-6641Medium· 6.4
1w ago

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the…

Sunlitdglingren · Media Library AssistantEPSS 0.22%via NVD
media_library_assistant vulnerabilities (CVEs) · VulnSea