Media Library Assistant Vulnerability

MEDIUM (5.4) No Patch (5 days)

Threat Intelligence

Low Risk
EPSS Score: 0.03% chance of exploitation (percentile: 6%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

Media Library Assistant is a WordPress plugin used to manage media files. It allows users to upload and manage images, videos, and audio files. The vulnerability in Media Library Assistant enables attackers to bypass access controls, potentially leading to unauthorized access to sensitive data.

Am I affected?

You're affected if you use Authorization Bypass Through User-Controlled Key vulnerability. Affected versions: 3.30 If you don't recognise this software, you're probably not affected.

Affected Products

DynamiApps / Media Library Assistant

How to fix

Upgrade to Media Library Assistant version 4.0.1 or later from the WordPress Plugin Directory (https://wordpress.org/plugins/media-library-assistant/) or through your hosting provider's plugin manager.
- If an immediate upgrade isn't possible, restrict network access to your WordPress installation and monitor for suspicious activity.

References