Executive brief
The Media Library Assistant WordPress plugin fails to properly sanitize user input in the mla_gallery shortcode, allowing authenticated users with contributor-level access to inject malicious scripts. When a page containing the injected shortcode is viewed by other users, the malicious scripts execute in their browsers, potentially leading to account compromise, session hijacking, or unauthorized actions on the website.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the mla_gallery shortcode's handling of the mla_link_href parameter when mla_output is set to 'paginate_links'. The root cause is insufficient input sanitization and output escaping: the _paginate_links() function processes the mla_link_href value through mla_process_shortcode_parameter() and _replace_query_parameter() without proper URL escaping, then outputs the result directly in href attributes without applying esc_url(). The attack requires authentication with at minimum contributor-level privileges, allowing an attacker to craft a malicious shortcode that persists in the page content. When any user accesses the page, the stored payload executes in their browser context. The vulnerability affects versions up to and including 3.35; patches are expected in subsequent releases.
Affected products
- WordPress Media Library Assistant up to and including 3.35
Timeline
- 2026-09-11: disclosed