Plugin Vulnerability Hub
Plugin 29 known issues Latest disclosed Apr 06, 2026

Media Library Assistant Vulnerabilities

Review known vulnerability records for the WordPress plugin Media Library Assistant (`media-library-assistant`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-34885, CVE-2026-34897 and CVE-2026-3072, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
29
High or Critical
8
Patch Coverage
100%
Last Updated
Apr 15, 2026
Priority CVE Quick Links

Fast paths into Media Library Assistant CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
29
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Media Library Assistant so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
29 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
2 critical and 6 high severity findings.
Recent CVEs
CVE-2026-34885, CVE-2026-34897 and CVE-2026-3072
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Media Library Assistant

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-34885
CVE-2026-34885: Media Library Assistant <= 3.34 - Authenticated (Contributor+) SQL Injection

The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.34 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticate...

Published
Apr 06, 2026
Patched Release
3.35
Affected Versions
Versions up to 3.34
Next Step
Update to 3.35 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-34897
CVE-2026-34897: Media Library Assistant <= 3.34 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and a...

Published
Apr 06, 2026
Patched Release
3.35
Affected Versions
Versions up to 3.34
Next Step
Update to 3.35 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-3072
CVE-2026-3072: Media Library Assistant <= 3.33 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification

The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mla_update_compat_fields_action() function in all versions up to, and including, 3.33. This makes it possible for authenticated attackers,...

Published
Mar 04, 2026
Patched Release
3.34
Affected Versions
Versions up to 3.33
Next Step
Update to 3.34 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-32399
CVE-2026-32399: Media LIbrary Assistant <= 3.32 - Authenticated (Contributor+) SQL Injection

The Media LIbrary Assistant plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticate...

Published
Feb 20, 2026
Patched Release
3.33
Affected Versions
Versions up to 3.32
Next Step
Update to 3.33 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11738
CVE-2025-11738: Media Library Assistant <= 3.29 - Unauthenticated Limited File Read

The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the s...

Published
Oct 17, 2025
Patched Release
3.30
Affected Versions
Versions up to 3.29
Next Step
Update to 3.30 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-63065
CVE-2025-63065: Media Library Assistant <= 3.29 - Missing Authorization

The Media Library Assistant plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.29. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Published
Oct 09, 2025
Patched Release
3.30
Affected Versions
Versions up to 3.29
Next Step
Update to 3.30 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-59590
CVE-2025-59590: Media Library Assistant <= 3.28 - Authenticated (Author+) Stored Cross-Site Scripting

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,...

Published
Sep 22, 2025
Patched Release
3.29
Affected Versions
Versions up to 3.28
Next Step
Update to 3.29 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-8357
CVE-2025-8357: Media Library Assistant <= 3.27 - Authenticated (Author+) Limited File Deletion

The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user capability checking in the _process_mla_download_file function in all versions up to, and including, 3....

Published
Aug 18, 2025
Patched Release
3.28
Affected Versions
Versions up to 3.27
Next Step
Update to 3.28 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-7035
CVE-2025-7035: Media Library Assistant <= 3.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attribu...

Published
Jul 15, 2025
Patched Release
3.27
Affected Versions
Versions up to 3.26
Next Step
Update to 3.27 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-31627
CVE-2025-31627: Media Library Assistant <= 3.24 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and...

Published
Mar 31, 2025
Patched Release
3.25
Affected Versions
Versions up to 3.24
Next Step
Update to 3.25 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-11974
CVE-2024-11974: Media Library Assistant <= 3.23 - Reflected Cross-Site Scripting via smc_settings_tab, unattachfixit-action, and woofixit-action Parameters

The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escap...

Published
Jan 03, 2025
Patched Release
3.24
Affected Versions
Versions up to 3.23
Next Step
Update to 3.24 or newer if supported.
Plugin High Patched: Yes CVE-2024-51661
CVE-2024-51661: Media Library Assistant <= 3.19 - Authenticated (Administrator+) Remote Code Execution

The Media Library Assistant plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.19. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

Published
Nov 01, 2024
Patched Release
3.20
Affected Versions
Versions up to 3.19
Next Step
Update to 3.20 or newer if supported.