Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2023-4634
Disclosure Date: September 06, 2023 (last updated November 09, 2023)
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.
0
Attacker Value
Unknown
CVE-2023-34010
Disclosure Date: August 05, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in submodule of David Lingren Media Library Assistant plugin <= 3.0.7 versions.
0
Attacker Value
Unknown
CVE-2022-41618
Disclosure Date: September 29, 2022 (last updated October 08, 2023)
Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.
0
Attacker Value
Unknown
CVE-2020-11928
Disclosure Date: April 20, 2020 (last updated November 27, 2024)
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
0
Attacker Value
Unknown
CVE-2020-11731
Disclosure Date: April 13, 2020 (last updated February 21, 2025)
The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/Media Library Assistant tabs, which allow remote authenticated users to execute arbitrary JavaScript.
0
Attacker Value
Unknown
CVE-2020-11732
Disclosure Date: April 13, 2020 (last updated November 27, 2024)
The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.
0
Attacker Value
Unknown
CVE-2018-20982
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens.
0