PT-2026-79304 · WordPress · Media Library Assistant

CVE-2026-16959

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Media Library Assistant versions prior to 3.40
Description Users with the Author role can perform SQL injection, a technique used to manipulate backend databases, because a search parameter is not validated before being concatenated into a SQL query within a media-library query handler. The issue occurs via the mla search connector.
Recommendations Update Media Library Assistant to version 3.40 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16959

Affected Products

Media Library Assistant