CVE-2020-11928: Davidlingren Media Library Assistant
Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
Affected products
- Davidlingren Media Library Assistant: before 2.82 (fixed in 2.82)
Published 2020-04-20. Last modified 2026-06-17.