Review
Media Library Assistant
CVE published 2026-08-21
CVE-2026-16959
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection. This vulnerability could allow attackers to extract or modify sensitive data, potentially leading to further exploitation of the affected system. Users with the Author [truncated]