PatchSiren

Media Library Assistant CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Media Library Assistant CVE published 2026-08-21

CVE-2026-16959

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection. This vulnerability could allow attackers to extract or modify sensitive data, potentially leading to further exploitation of the affected system. Users with the Author [truncated]