Media Library Assistant

Vulnerabilities 31Slug media-library-assistantLatest version 3.35WordPress.org →

Minimum safe version

3.35

Update to 3.35 or later to address 31 fixable vulnerabilities

Latest available3.35
Medium 5.9
2025-09-22< 3.29

Media Library Assistant <= 3.28 - Authenticated (Author+) Stored Cross-Site Scripting

N/A
2026-03-04< 3.34

Media Library Assistant <= 3.33 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification

Medium 4.3
2025-08-19< 3.28

Media Library Assistant <= 3.27 - Authenticated (Author+) Limited File Deletion

Medium 6.4
2025-07-16< 3.27

Media Library Assistant <= 3.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes

Medium 6.5
2024-05-22< 3.16

WordPress Media Library Assistant Plugin <= 3.15 is vulnerable to SQL Injection

Medium 6.1
2024-05-22< 3.16

WordPress Media Library Assistant Plugin <= 3.15 is vulnerable to Cross Site Scripting (XSS)

N/A
< 2.90

Media Library Assistant &lt; 2.90 - Authenticated Blind SQL Injection

N/A
2020-11-24< 2.9.0

WordPress Media Library Assistant plugin <= 2.84 - Authenticated Blind SQL Injection (SQLi) vulnerability