Impact
The Media Library Assistant plugin allows an authenticated attacker with contributor‑level permissions to inject arbitrary JavaScript via the mla_link_href shortcode parameter when mla_output is set to paginate_links. The input from the parameter is processed without proper URL escaping and is output directly in a link’s href attribute, enabling the attacker to store malicious code that executes whenever a user views a page containing the injected shortcode. This flaw‑79) that can compromise the confidentiality and integrity of any visitor’s session data and can be used to deliver phishing, malware, or other malicious payloads.
Affected Systems
dglingren’s Media Library Assistant WordPress plugin, versions up to and including 3.35, is affected when installed on any WordPress site.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate impact if exploited. EPSS is not available, and the filter is not listed in KEV, suggesting no widely known active exploitation. The likely attack vector requires the adversary to authenticate on the target site with at least contributor privileges and then embed the malicious shortcode in a section of the site that renders on public pages. Once inserted, the persistence of the injected code exposes all site visitors until remediated, raising a moderate risk due to the need for legitimate site access but sustained exposure.
OpenCVE Enrichment