CVE-2018-20982: Davidlingren Media Library Assistant

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens.

Affected products

  • Davidlingren Media Library Assistant: before 2.74 (fixed in 2.74)

Published 2019-08-22. Last modified 2026-06-17.