Executive brief
Media Library Assistant is a popular WordPress plugin that manages media files and uploads within WordPress sites. The plugin contains an arbitrary file upload vulnerability that allows authenticated authors to upload malicious files to the server, potentially leading to complete site compromise and server takeover.
Technical details
The Media Library Assistant plugin versions 3.39 and earlier contain an arbitrary file upload vulnerability in its file upload handling mechanism. The vulnerability allows authenticated users with author-level privileges to bypass file type validation and upload arbitrary files (including executable code) to the server. The attack requires valid WordPress author credentials but no additional user interaction. An attacker can leverage this to upload web shells or other malicious payloads, resulting in remote code execution and complete compromise of the affected WordPress installation. The vulnerability was patched in version 3.40.
Affected products
- David Lingren Media Library Assistant ≤ 3.39
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Version 3.40 released