Beta

Report

Media Library Assistant <= 3.19 is vulnerable to Remote Code Execution (RCE) vulnerability

Administrator
Published
2024-10-31

The Media Library Assistant plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.19. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

CVSS

Score:9.1

Severity:Critical

Version: 3.19

There is a patch available in v3.20 and we strongly recommend you update to this version as soon as possible.