Junglewise Threat Intelligence

CVE-2026-16959: Media Library Assistant SQL injection in search connector

CVE-2026-16959 · Severity: medium · CVSS 6.8 · Published 2026-08-21

Technologies: Download Media Library Assistant Media Library Assistant.

Executive brief

The Media Library Assistant WordPress plugin contains a SQL injection vulnerability in its media search handler. An authenticated user with Author privileges can inject arbitrary SQL commands through an unsanitized search parameter, potentially exposing or manipulating the WordPress database. This could allow an attacker to extract sensitive data, modify posts or user information, or escalate privileges within the WordPress installation.

Technical details

The vulnerability is a classic SQL injection (CWE-89) caused by insufficient input validation on the mla_search_connector parameter before concatenation into a SQL query in the media-library query handler. The attack requires an authenticated user account with the Author role (upload_files capability) and at least one attachment in the media library. No CSRF token (nonce) is required. An attacker can craft a POST request to wp-admin/admin-ajax.php with a malicious mla_search_connector value to execute arbitrary SQL commands. The vulnerability has been patched in version 3.40; users on versions before 3.40 should upgrade immediately.

Affected products

  • Download Media Library Assistant Media Library Assistant before 3.40

Timeline

  • 2026-08-19: disclosed
  • 2026-08-20: patched: Fixed in version 3.40

References