Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41.
Published: 2026-10-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises from improper neutralization of input during web page generation, allowing an attacker to store malicious script code within the Media Library Assistant plugin. When a page is rendered, the unsanitized content is included without encoding, which can execute arbitrary JavaScript in the browsers of users who view the affected page. This stored XSS can lead to session hijacking, defacement, or the execution of further malicious payloads on the site.

Affected Systems

The affected product is the Media Library Assistant plugin authored by David Lingren. All released versions up to and including 3.41 are vulnerable; the issue is mitigated in versions 3.42 and later.

Risk and Exploitability

The CVSS score of 7.1 classifies this flaw as high severity. The EPSS score is not available, so the exact exploitation probability is unclear. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an attacker to be able to input data into the plugin—providing stored, executable JavaScript that is later delivered to site visitors. Without explicit details on authentication requirements, it is inferred that the attacker needs sufficient privileges to add content through the plugin, but the lack of that information limits precise risk assessment.

Generated by OpenCVE AI on October 9, 2026 at 11:45 UTC.

Remediation

Vendor Solution

Update the WordPress Media LIbrary Assistant plugin to the latest available version (at least 3.42).


OpenCVE Recommended Actions

  • Update the Media Library Assistant plugin to version 3.42 or later.
  • Disable or remove the Media Library Assistant plugin if it is not required for operations.
  • Ensure WordPress core and all other plugins are kept up‑to‑date to reduce overall exposure to similar injection attacks.

Generated by OpenCVE AI on October 9, 2026 at 11:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41.
Title WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:20.474Z

Reserved: 2026-09-22T09:18:20.380Z

Link: CVE-2026-95609

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T10:16:43.193

Modified: 2026-10-09T13:20:48.273

Link: CVE-2026-95609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:00:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')