Media Library Assistant <= 3.28 - Authenticated (Author+) Stored Cross-Site Scripting
Media Library Assistant
Minimum safe version
3.35
Update to 3.35 or later to address 31 fixable vulnerabilities
Media Library Assistant <= 3.33 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification
CVE-2026-34885
CVE-2026-34897
CVE-2026-32399
CVE-2025-63065
CVE-2025-11738
Media Library Assistant <= 3.27 - Authenticated (Author+) Limited File Deletion
Media Library Assistant <= 3.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes
CVE-2025-31627
CVE-2024-11974
CVE-2024-51661
CVE-2024-6823
CVE-2024-5544
CVE-2024-5605
WordPress Media Library Assistant Plugin <= 3.15 is vulnerable to SQL Injection
WordPress Media Library Assistant Plugin <= 3.15 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-2475
CVE-2024-2871
CVE-2023-24385
CVE-2023-4716
CVE-2023-4634
CVE-2023-34010
Media Library Assistant < 2.90 - Authenticated Blind SQL Injection
CVE-2023-0279
CVE-2022-41618
WordPress Media Library Assistant plugin <= 2.84 - Authenticated Blind SQL Injection (SQLi) vulnerability
CVE-2018-20982
CVE-2020-11732
CVE-2020-11731
CVE-2020-11928