Executive brief
Media Library Assistant is a popular WordPress plugin for managing media files. A cross-site scripting (XSS) vulnerability in versions up to 3.39 allows attackers with subscriber-level access to inject malicious scripts that can steal visitor data or hijack user accounts, requiring a privileged user to click a malicious link or perform an action to trigger the exploit.
Technical details
The vulnerability is a stored or reflected cross-site scripting (XSS) flaw in Media Library Assistant plugin versions 3.39 and earlier. It requires subscriber-level privileges and user interaction (e.g., clicking a link or visiting a crafted page) to exploit successfully. An attacker can inject malicious JavaScript that executes in the context of other users' browsers, potentially stealing session tokens, admin credentials, or visitor data. The vulnerability was patched in version 3.40 released on 19 August 2026.
Affected products
- David Lingren Media Library Assistant <= 3.39
Timeline
- 2026-08-19: disclosed: Published on Patchstack
- 2026-08-20: patched: Version 3.40 released