Cross-site Scripting Vulnerability in Media Library Assistant by David Lingren Media
CVE-2026-95609

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-95609?

The Media Library Assistant, developed by David Lingren Media, is susceptible to a stored cross-site scripting (XSS) vulnerability. This vulnerability arises from improper neutralization of user inputs during web page generation, allowing attackers to inject malicious scripts into the pages viewed by users. This security flaw impacts versions of Media Library Assistant up to 3.41, potentially compromising the integrity and confidentiality of data within WordPress sites. It is critical for users to update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

Media LIbrary Assistant 0 <= 3.41

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nh4tvd | Patchstack Bug Bounty Program
.