Impact
The vulnerability allows an attacker to bypass the plugin's access restrictions by manipulating a user‑controlled key. This means a non‑privileged user can access or alter media items that should be restricted, jeopardizing confidentiality and integrity of media content. The weakness is classified as CWE‑639.
Affected Systems
David Lingren Media LIbrary Assistant plugin for WordPress, versions up to and including 3.29, are affected. Later releases, starting with 3.30, contain a fix. The vulnerability applies to any site running the plugin within that version range.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog, further indicating limited active exploitation. Attackers would need to access the site’s front end or use the plugin’s exposed management URLs to send a crafted request with a manipulated key. Once the bypass is achieved they could read or modify media records that would otherwise be protected by WordPress role checks.
OpenCVE Enrichment