Impact
The Media Library Assistant plugin (versions 3.41 and earlier) contains a contributor‑level SQL Injection flaw, allowing an attacker to inject arbitrary SQL code into database queries. This weakness, identified as CWE‑89, gives the attacker the ability to read, modify, or delete sensitive data stored in the WordPress database, potentially compromising site confidentiality, integrity, or availability. The impact is limited to WordPress sites that have the vulnerable plugin installed and are accessed by users with contributor privileges or higher.
Affected Systems
Vendors involved include developer David Lingren. The affected product is the WordPress Media Library Assistant plugin, with all releases up to and including version 3.41. Administrators should verify that any instance of this plugin is updated to version 3.42 or newer where the SQL injection vector has been closed.
Risk and Exploitability
The CVSS score of 8.5 classifies this issue as high severity. The EPSS score is currently not available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires web access to a WordPress site running the vulnerable plugin and a contributor‑level user account. If an attacker gains such access, they can execute arbitrary SQL statements, which could lead to data exfiltration, data tampering, or disruption of site functionality.
OpenCVE Enrichment