Impact
The vulnerability arises from improper neutralization of input during web page generation, allowing an attacker to store malicious script code within the Media Library Assistant plugin. When a page is rendered, the unsanitized content is included without encoding, which can execute arbitrary JavaScript in the browsers of users who view the affected page. This stored XSS can lead to session hijacking, defacement, or the execution of further malicious payloads on the site.
Affected Systems
The affected product is the Media Library Assistant plugin authored by David Lingren. All released versions up to and including 3.41 are vulnerable; the issue is mitigated in versions 3.42 and later.
Risk and Exploitability
The CVSS score of 7.1 classifies this flaw as high severity. The EPSS score is not available, so the exact exploitation probability is unclear. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an attacker to be able to input data into the plugin—providing stored, executable JavaScript that is later delivered to site visitors. Without explicit details on authentication requirements, it is inferred that the attacker needs sufficient privileges to add content through the plugin, but the lack of that information limits precise risk assessment.
OpenCVE Enrichment