CVE-2020-11731: Davidlingren Media Library Assistant
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
The Media Library Assistant plugin before 2.82 for Wordpress suffers from multiple XSS vulnerabilities in all Settings/Media Library Assistant tabs, which allow remote authenticated users to execute arbitrary JavaScript.
Affected products
- Davidlingren Media Library Assistant: before 2.82 (fixed in 2.82)
Published 2020-04-13. Last modified 2026-06-17.