Impact
The vulnerability is a reflected cross‑site scripting flaw that allows any unauthenticated user to inject arbitrary JavaScript code into the Media Library Assistant plugin, potentially enabling malicious scripts to run in the browsers of site visitors.
Affected Systems
WordPress Media Library Assistant plugin versions 3.35 and older are affected. The vendor, David Lingren, recommends updating to version 3.36 or newer.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. With an EPSS score of less than 1%, exploitation is considered unlikely under typical conditions, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to supply crafted input to a target site to trigger reflected script execution, which can be achieved without authentication, making the attack surface wide and accessible from any network.
OpenCVE Enrichment