PT-2026-79304 · WordPress · Media Library Assistant
CVE-2026-16959
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Media Library Assistant versions prior to 3.40
Description
Users with the Author role can perform SQL injection, a technique used to manipulate backend databases, because a search parameter is not validated before being concatenated into a SQL query within a media-library query handler. The issue occurs via the
mla search connector.Recommendations
Update Media Library Assistant to version 3.40 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Media Library Assistant