Impact
The vulnerability is an unauthenticated Cross‑Site Scripting flaw in the WordPress Media Library Assistant plugin version 3.38 and earlier. The plugin does not properly escape or validate user input, allowing an attacker to inject malicious JavaScript that executes in the browsers of any visitor to a page that renders data from the plugin. Because the attack does not require authentication, an attacker can hijack user sessions, deface content, or exfiltrate stored credentials from the victim’s browser. This flaw is listed as CWE‑79.
Affected Systems
All installations of the Media Library Assistant plugin, developed by David Lingren, running version 3.38 or lower, are vulnerable. Any WordPress site that has this plugin enabled, regardless of the overall WordPress version, is at risk. No additional system components are targeted beyond the plugin itself.
Risk and Exploitability
The CVSS base score of 7.1 classifies the issue as medium severity. Exploitability is high: a web‑based attacker can send a crafted request through the plugin’s interface or a link that includes the malicious input. The EPSS score for this vulnerability is not available, and the flaw is not listed in CISA’s KEV catalog. As the attack vector is purely web interface and no privileged access is required, the risk to exposed sites is substantial. Nevertheless, the lack of a published exploit at this time suggests that accidental or opportunistic abuse is more likely than a coordinated attack.
OpenCVE Enrichment