SQL Injection Vulnerability in Media Library Assistant by David Lingren
CVE-2026-56012
8.5HIGH
What is CVE-2026-56012?
A vulnerability exists in the Media Library Assistant plugin developed by David Lingren, which permits an attacker to execute blind SQL injection attacks. This flaw allows for the manipulation of SQL queries, potentially compromising the database and exposing sensitive information. The vulnerability affects versions of the plugin up to and including 3.35, enabling unauthorized access and exploitation of the database structure within WordPress sites utilizing this plugin.
Affected Version(s)
Media LIbrary Assistant <= 3.35