Executive brief
The Media Library Assistant plugin for WordPress, which helps users manage and organize their website's media files, is vulnerable to a blind SQL injection attack. An attacker with basic contributor-level access can use this flaw to interact directly with the website's database. This could lead to the unauthorized extraction of sensitive information, potentially compromising user data or site configuration.
Technical details
A blind SQL injection vulnerability exists in the David Lingren Media Library Assistant plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw is present in versions up to and including 3.35. An attacker with 'Contributor' or higher privileges can exploit this vulnerability via network requests to execute arbitrary SQL queries against the backend database. While the impact is categorized as 'blind,' it allows for the exfiltration of sensitive data. The issue is addressed in version 3.36.
Affected products
- David Lingren Media Library Assistant through 3.35
Timeline
- 2026-05-04: other: Reported by researcher daroo
- 2026-06-18: disclosed: Early warning sent to Patchstack customers
- 2026-06-18: advisory: Public advisory published by Patchstack and NVD
- 2026-06-18: patched: Patch released in version 3.36