CVE-2020-11928: Davidlingren Media Library Assistant

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.

Affected products

  • Davidlingren Media Library Assistant: before 2.82 (fixed in 2.82)

Published 2020-04-20. Last modified 2026-06-17.