Authorization Bypass Vulnerability in Media Library Assistant by David Lingren
CVE-2025-63065

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 December 2025

What is CVE-2025-63065?

A vulnerability exists in the Media Library Assistant plugin developed by David Lingren, which allows attackers to exploit incorrectly configured access control settings. This flaw enables unauthorized users to bypass security levels, potentially giving them access to restricted resources within the plugin. The vulnerability affects versions of Media Library Assistant from n/a to 3.30, posing risks to users who may rely on this plugin for managing media assets.

Affected Version(s)

Media Library Assistant <= n/a

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Certus Cybersecurity | Patchstack Bug Bounty Program
.