PT-2020-12927 · WordPress · Media Library Assistant

Published

2020-04-19

·

Updated

2023-08-07

·

CVE-2020-11928

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions media-library-assistant plugin versions prior to 2.82 for WordPress
Description The issue allows for Remote Code Execution via the tax query, meta query, or date query parameter in mla gallery through an admin interface.
Recommendations For versions prior to 2.82, update to version 2.82 or later to resolve the issue. As a temporary workaround, consider restricting access to the mla gallery function and its associated parameters tax query, meta query, and date query until the update is applied.

Fix

Related Identifiers

CVE-2020-11928

Affected Products

Media Library Assistant