PT-2026-44771 · WordPress · Media Library Assistant
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Media Library Assistant versions prior to 3.36
Description
The Media Library Assistant plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF), a type of attack where an unauthorized user tricks a victim into performing actions they did not intend to do. This occurs because of missing nonce verification—a security token used to ensure a request is legitimate—within the bulk action handlers of the settings tab. Consequently, unauthenticated attackers can deceive an administrator into executing bulk delete, edit, or purge operations on plugin settings and attachment metadata through a forged request.
Recommendations
Update to a version later than 3.35.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Media Library Assistant