CVE-2026-16959
Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.
| Vendor | unknown |
| Product | media library assistant |
| Published | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown media library assistant
Be the first to know when new unknown vulnerabilities affecting unknown media library assistant are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Media Library Assistant
0 < 3.40
References
Credits
Joรฃo Ramos Maciel WPScan