Stored Cross-Site Scripting in Media Library Assistant Plugin for WordPress
CVE-2026-6640

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 September 2026

What is CVE-2026-6640?

The Media Library Assistant plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping in the 'mla_link_attributes' parameter. This flaw allows authenticated users with contributor-level access and higher to execute arbitrary scripts in pages, which can lead to unauthorized actions when other users view the affected pages. All versions of the plugin up to and including 3.35 are impacted, making it crucial for administrators to update and implement security best practices.

Affected Version(s)

Media Library Assistant 0 <= 3.35

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

normaandersonfrank
.