Cross-Site Scripting Vulnerability in Media Library Assistant by David Lingren
CVE-2026-34897
6.5MEDIUM
What is CVE-2026-34897?
The Media Library Assistant plugin, designed for WordPress, is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts. This vulnerability occurs due to improper handling of user input during web page generation, enabling stored XSS attacks. Users of Media Library Assistant up to version 3.34 should take immediate actions to mitigate risks and secure their websites.
Affected Version(s)
Media LIbrary Assistant <= 3.34