Arbitrary File Upload Vulnerability in Media Library Assistant Plugin by WordPress
CVE-2026-66600
9.1CRITICAL
What is CVE-2026-66600?
The Media Library Assistant plugin for WordPress prior to version 3.39 is vulnerable to arbitrary file upload, allowing unauthorized users to upload malicious files to the server. This could lead to potential exploitation and compromise of the website, exposing sensitive data or further manipulation by attackers. Website administrators should ensure they upgrade to the latest version to mitigate this risk.
Affected Version(s)
Media LIbrary Assistant <= 3.39