Stored Cross-Site Scripting in Media Library Assistant Plugin for WordPress
CVE-2026-6640
6.4MEDIUM
What is CVE-2026-6640?
The Media Library Assistant plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the 'mla_link_attributes' parameter. This flaw allows authenticated users with contributor-level access and higher to execute arbitrary scripts in pages, which can lead to unauthorized actions when other users view the affected pages. All versions of the plugin up to and including 3.35 are impacted, making it crucial for administrators to update and implement security best practices.
Affected Version(s)
Media Library Assistant 0 <= 3.35