Stored Cross-Site Scripting Vulnerability in Media Library Assistant for WordPress
CVE-2026-6642

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 September 2026

What is CVE-2026-6642?

The Media Library Assistant plugin for WordPress is exposed to Stored Cross-Site Scripting due to inadequate output escaping in the bulk edit preset export/import functionality. This vulnerability arises when preset field values are rendered in HTML attribute contexts, allowing authenticated attackers with Author-level access or higher to inject malicious web scripts. As these injected scripts execute upon administrator interaction with the imported presets, the risks of data compromise and exploitation increase significantly. Immediate attention is required to ensure proper escaping mechanisms are applied to prevent attribute injection attacks.

Affected Version(s)

Media Library Assistant 0 <= 3.35

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TruongLV1 From FPT Night Wolf
.