๐Ÿ” CVE Alert

CVE-2026-16959

UNKNOWN 0.0

Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.

Vendor unknown
Product media library assistant
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for unknown media library assistant

Be the first to know when new unknown vulnerabilities affecting unknown media library assistant are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Media Library Assistant
0 < 3.40

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7b13e3d3-42ee-4fe2-bb47-75bd2273f1b0/

Credits

Joรฃo Ramos Maciel WPScan