The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive information.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 18 Oct 2025 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive information. | |
Title | Media Library Assistant <= 3.29 - Unauthenticated Limited File Read | |
Weaknesses | CWE-73 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-10-18T05:41:55.159Z
Reserved: 2025-10-14T13:25:58.992Z
Link: CVE-2025-11738

No data.

Status : Received
Published: 2025-10-18T06:15:37.123
Modified: 2025-10-18T06:15:37.123
Link: CVE-2025-11738

No data.

No data.