Description
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
Published: 2026-08-20
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Subscriber Cross Site Scripting (XSS) is present in Media Library Assistant versions up to 3.39. A malicious subscriber can inject script code that is stored and later rendered in the WordPress media library interface, potentially allowing defacement, cookie theft, or other client‑side attacks.

Affected Systems

The vulnerability affects the Media Library Assistant plugin developed by David Lingren. All WordPress sites that have the plugin installed at version 3.39 or earlier are impacted; newer releases such as 3.40 and above contain the fix.

Risk and Exploitability

The CVSS score of 6.5 places this issue in the medium impact range. Because EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, no current exploitation data exists. Based on the description, the likely attack vector involves an authenticated subscriber submitting input that bypasses validation, causing the injected script to be stored and executed when the media library page is viewed.

Generated by OpenCVE AI on August 20, 2026 at 21:03 UTC.

Remediation

Vendor Solution

Update the WordPress Media LIbrary Assistant Plugin to the latest available version (at least 3.40).


OpenCVE Recommended Actions

  • Update the Media Library Assistant plugin to version 3.40 or later.
  • Audit the media library for any stored scripts and remove malicious entries.
  • Configure a content security policy or install a security plugin that blocks inline script execution to prevent residual XSS attacks.

Generated by OpenCVE AI on August 20, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Davidlingren
Davidlingren media Library Assistant
Wordpress
Wordpress wordpress
Vendors & Products Davidlingren
Davidlingren media Library Assistant
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
Title WordPress Media LIbrary Assistant plugin <= 3.39 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Davidlingren Media Library Assistant
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T15:19:09.602Z

Reserved: 2026-07-27T14:00:08.990Z

Link: CVE-2026-66601

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:33.933

Modified: 2026-08-20T16:17:43.413

Link: CVE-2026-66601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T21:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')