
Cloud Vulnerability DB
A community-led vulnerabilities database
The Media Library Assistant plugin before version 2.82 for WordPress contains multiple Cross-Site Scripting (XSS) vulnerabilities in all Settings/Media Library Assistant tabs. The vulnerability was discovered on December 15, 2019 and publicly disclosed on April 13, 2020 (NVD, CVE).
The vulnerability allows remote authenticated users to execute arbitrary JavaScript code through the Settings/Media Library Assistant tabs. The issue received a CVSS v3.1 Base Score of 6.1 MEDIUM (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) (NVD).
If exploited, this vulnerability could allow authenticated attackers to inject and execute malicious JavaScript code in the context of other users' browsers who access the affected pages, potentially leading to session hijacking, credential theft, or other client-side attacks (NVD).
Users should upgrade to Media Library Assistant version 2.82 or later which contains fixes for these XSS vulnerabilities (WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."