Impact
Improper neutralization of user‑supplied input during page generation allows stored cross‑site scripting. Attackers could inject malicious script into the plugin’s persistent storage, which will execute in the browser of any user who views the affected page, potentially compromising session cookies, defacing content, or enabling further compromise.
Affected Systems
The Media Library Assistant plugin released by David Lingren, versions up to and including 3.34, contains the flaw. Users running these versions without updating remain vulnerable.
Risk and Exploitability
The flaw has a CVSS score of 6.5, indicating moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need authenticated access to the WordPress administration interface to inject the payload, after which any visitor to the affected page would be impacted.
OpenCVE Enrichment