Stored Cross-Site Scripting Vulnerability in Media Library Assistant for WordPress
CVE-2026-6642
6.4MEDIUM
What is CVE-2026-6642?
The Media Library Assistant plugin for WordPress is exposed to Stored Cross-Site Scripting due to inadequate output escaping in the bulk edit preset export/import functionality. This vulnerability arises when preset field values are rendered in HTML attribute contexts, allowing authenticated attackers with Author-level access or higher to inject malicious web scripts. As these injected scripts execute upon administrator interaction with the imported presets, the risks of data compromise and exploitation increase significantly. Immediate attention is required to ensure proper escaping mechanisms are applied to prevent attribute injection attacks.
Affected Version(s)
Media Library Assistant 0 <= 3.35