Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media Library Assistant allows Stored XSS. This issue affects Media Library Assistant: from n/a through 3.28.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-30471 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media Library Assistant allows Stored XSS. This issue affects Media Library Assistant: from n/a through 3.28. |
Fixes
Solution
Update the WordPress Media Library Assistant plugin to the latest available version (at least 3.29).
Workaround
No workaround given by the vendor.
References
History
Tue, 23 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Davidlingren
Davidlingren media Library Assistant Wordpress Wordpress wordpress |
|
Vendors & Products |
Davidlingren
Davidlingren media Library Assistant Wordpress Wordpress wordpress |
Mon, 22 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media Library Assistant allows Stored XSS. This issue affects Media Library Assistant: from n/a through 3.28. | |
Title | WordPress Media Library Assistant Plugin <= 3.28 - Cross Site Scripting (XSS) Vulnerability | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-09-23T17:51:10.734Z
Reserved: 2025-09-17T18:01:27.391Z
Link: CVE-2025-59590

No data.

Status : Awaiting Analysis
Published: 2025-09-22T19:16:27.590
Modified: 2025-09-22T21:22:16.313
Link: CVE-2025-59590

No data.

Updated: 2025-09-23T16:05:30Z