CVE-2020-11731: Davidlingren Media Library Assistant

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/Media Library Assistant tabs, which allow remote authenticated users to execute arbitrary JavaScript.

Affected products

  • Davidlingren Media Library Assistant: before 2.82 (fixed in 2.82)

Published 2020-04-13. Last modified 2026-06-17.