Arbitrary File Upload Vulnerability in Media Library Assistant Plugin by WordPress
CVE-2026-66600

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2026

What is CVE-2026-66600?

The Media Library Assistant plugin for WordPress prior to version 3.39 is vulnerable to arbitrary file upload, allowing unauthorized users to upload malicious files to the server. This could lead to potential exploitation and compromise of the website, exposing sensitive data or further manipulation by attackers. Website administrators should ensure they upgrade to the latest version to mitigate this risk.

Affected Version(s)

Media LIbrary Assistant <= 3.39

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nh4tvd | Patchstack Bug Bounty Program
.