Impact
Media Library Assistant prior to version 3.40 concatenates an unchecked search parameter directly into a SQL query. This omission allows any site user with the Author role to inject arbitrary SQL statements. The vulnerability enables data read/write or database manipulation, potentially exposing sensitive data or altering site content.
Affected Systems
The affected product is the Media Library Assistant WordPress plugin, any installation running a version lower than 3.40. The plugin is commonly used in WordPress sites for media management.
Risk and Exploitability
The attacker must be authenticated with at least the Author role, so the vulnerability only applies to legitimate users on the site. No public exploit references are available, and the EPSS score is not provided; the occurrence remains unlisted in the KEV catalog. Nonetheless, because the flaw permits arbitrary SQL execution, the impact could be severe if not mitigated promptly.
OpenCVE Enrichment