Impact
The Media Library Assistant plugin for WordPress contains a stored cross‑site scripting flaw introduced by the mla_link_attributes parameter. Inadequate input sanitization and output escaping allow an authenticated user with contributor role or higher to embed arbitrary of any visitor to the affected page.
Affected Systems
The flaw affects the dglingren Media Library Assistant plugin for WordPress. All releases through version 3.35, inclusive, are vulnerable. WordPress sites running these versions should verify their installed plugin version and plan an update.
Risk and Exploitability
The CVSS v3 score is 6.4, indicating moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The flaw is not listed in CISA KEV. Attack requires authenticated access at contributor level or higher; once authenticated, code can be stored and executed whenever the page is accessed.
OpenCVE Enrichment