Executive brief
Media Library Assistant is a WordPress plugin used to manage and enhance the site's media gallery. A security flaw in versions 3.35 and earlier allows an attacker to trick a site administrator or visitor into clicking a malicious link, which then executes unauthorized code in their browser. This could lead to the theft of login sessions, unauthorized website changes, or the redirection of users to malicious websites.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Media Library Assistant plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability can be exploited by an unauthenticated attacker who crafts a malicious URL and convinces a privileged user to click it. Because the application fails to properly sanitize input before rendering it back to the browser, the attacker's script executes within the context of the victim's session. This can result in session hijacking, cookie theft, or unauthorized administrative actions. The issue is resolved in version 3.36.
Affected products
- David Lingren Media Library Assistant <= 3.35
Timeline
- 2026-05-17: other: Reported by researcher Bonds
- 2026-06-15: advisory: Patchstack advisory published
- 2026-06-16: disclosed: CVE published to NVD
- 2026-06-15: patched: Version 3.36 released to address the vulnerability