PatchSiren

dglingren CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM dglingren CVE published 2026-09-11

CVE-2026-6642

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts. The vulnerability exists in the mla_generate_bulk_edit_form_fieldsets() function and mla-bulk-edit-fieldsets. [truncated]

MEDIUM dglingren CVE published 2026-09-11

CVE-2026-6641

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the _paginate_links() function processes the value through mla_process_shortcode_parameter() and [truncated]

MEDIUM dglingren CVE published 2026-09-11

CVE-2026-6640

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts, which execute when a user accesses an injected p [truncated]