A high-severity SQL injection vulnerability was found in the Media Library Assistant plugin, affecting versions up to 3.35. This vulnerability, tracked as CVE-2026-56012, has a CVSS score of 8.5 and allows attackers to perform blind SQL injection attacks. The vulnerability was publicly disclosed on June 18, 2026. Users of the plugin should take immediate action to mitigate the risk. The vulnerability is c [truncated]
CVE-2026-54198 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Media Library Assistant versions up to and including 3.35. The vulnerability has a CVSS score of 7.1 and was published on 2026-06-16T10:16:28.730Z. The vulnerability allows an unauthenticated attacker to inject malicious JavaScript code, potentially leading to unauthorized actions or data exposure. The affected p [truncated]