Impact
Subscriber Cross Site Scripting (XSS) is present in Media Library Assistant versions up to 3.39. A malicious subscriber can inject script code that is stored and later rendered in the WordPress media library interface, potentially allowing defacement, cookie theft, or other client‑side attacks.
Affected Systems
The vulnerability affects the Media Library Assistant plugin developed by David Lingren. All WordPress sites that have the plugin installed at version 3.39 or earlier are impacted; newer releases such as 3.40 and above contain the fix.
Risk and Exploitability
The CVSS score of 6.5 places this issue in the medium impact range. Because EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, no current exploitation data exists. Based on the description, the likely attack vector involves an authenticated subscriber submitting input that bypasses validation, causing the injected script to be stored and executed when the media library page is viewed.
OpenCVE Enrichment