CVE-2024-6823: Davidlingren Media Library Assistant
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected products
- Davidlingren Media Library Assistant: before 3.19 (fixed in 3.19)
Published 2024-08-13. Last modified 2026-06-17.