Junglewise Threat Intelligence

CVE-2026-66600: WordPress Media Library Assistant arbitrary file upload

CVE-2026-66600 · Severity: critical · CVSS 9.1 · Published 2026-08-20

Technologies: David Lingren Media Library Assistant. Vendors: David Lingren.

Executive brief

Media Library Assistant is a popular WordPress plugin that manages media files and uploads within WordPress sites. The plugin contains an arbitrary file upload vulnerability that allows authenticated authors to upload malicious files to the server, potentially leading to complete site compromise and server takeover.

Technical details

The Media Library Assistant plugin versions 3.39 and earlier contain an arbitrary file upload vulnerability in its file upload handling mechanism. The vulnerability allows authenticated users with author-level privileges to bypass file type validation and upload arbitrary files (including executable code) to the server. The attack requires valid WordPress author credentials but no additional user interaction. An attacker can leverage this to upload web shells or other malicious payloads, resulting in remote code execution and complete compromise of the affected WordPress installation. The vulnerability was patched in version 3.40.

Affected products

  • David Lingren Media Library Assistant ≤ 3.39

Timeline

  • 2026-08-20: disclosed
  • 2026-08-19: patched: Version 3.40 released

References

Related threats