Impact
The Media Library Assistant plugin for WordPress contains a flaw where user‑supplied data is not properly neutralized before inclusion in web pages, enabling an attacker to inject malicious scripts that persist across user sessions. This stored cross‑site scripting flaw can compromise confidentiality, integrity and availability of the site through the user interface, allowing an attacker to exfiltrate data, hijack sessions or deface content. The vulnerability is classified as CWE‑79.
Affected Systems
All versions of the David Lingren Media Library Assistant plugin up to and including 3.39 are affected. The flaw appears in the WordPress plugin environment where the plugin processes media library metadata or input fields.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate risk with moderate impact if exploited. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw by injecting malicious payloads into fields managed by the plugin; the stored nature means that any user who views a page containing the stored data will execute the script. The typical attack path requires the attacker to have ability to submit or modify content managed by the plugin or to upload a file that inserts malicious code into the plugin's data store.
OpenCVE Enrichment