SecAlerts
d

davidlingren

Security Risk Profile

36
/100
low

Security Risk Score

Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 22, 2019 to present

19
Total CVEs
8
Critical+High
1
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
36/100
low
⚠️ 1 Active Exploits

Severity Distribution

Critical
3
High
5
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
5

Age Distribution

Common Weaknesses (CWE)

1
XSS
10
2
SQL Injection
3
3
OS Command Injection
1
4
Command Injection
1
5
Malicious File Upload
1

Most Affected Products

1. Davidlingren Media Library Assistant Wordpress19
2. Media Library Assistant Media Library Assistant6
3. WordPress Media Library Assistant1

Recent Vulnerabilities

See more →
CVE-2025-7035
CVSS 6.4EPSS 0%medium

Media Library Assistant <= 3.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes

Jul 16, 2025🔧 No Patch
CVE-2024-11974
CVSS 6.1medium

Media Library Assistant <= 3.23 - Reflected Cross-Site Scripting via smc_settings_tab, unattachfixit-action, and woofixit-action Parameters

Jan 4, 2025
CVE-2024-51661
CVSS 9.1critical

WordPress Media Library Assistant plugin <= 3.19 - Remote Code Execution (RCE) vulnerability

Nov 4, 2024
CVE-2024-6823
CVSS 8.8EPSS 0%high

Media Library Assistant <= 3.18 - Authenticated (Author+) Arbitrary File Upload via mla-inline-edit-upload-scripts AJAX Action

Aug 13, 2024
CVE-2024-5544
CVSS 6.1EPSS 0%medium

Media Library Assistant <= 3.17 - Reflected Cross-Site Scripting

Jul 2, 2024🔧 No Patch
CVE-2024-5605
CVSS 8.8EPSS 0%high

Media Library Assistant <= 3.16 - Authenticated (Contributor+) SQL Injection via order Parameter

Jun 20, 2024🔧 No Patch
CVE-2024-3518
CVSS 8.8high

Media Library Assistant <= 3.15 - Authenticated (Contributor+) SQL Injection via Shortcode

May 21, 2024
CVE-2024-3519
CVSS 6.1medium

Media Library Assistant <= 3.15 - Reflected Cross-Site Scripting via lang

May 21, 2024
CVE-2024-2871
CVSS 7.7EPSS 0%high

Media Library Assistant <= 3.13 - Authenticated (Contributor+) SQL Injection via Shortcode

Apr 9, 2024🔧 No Patch
CVE-2024-2475
CVSS 6.4medium

Media Library Assistant <= 3.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_gallery Shortcode

Mar 29, 2024🔧 No Patch

Monitor davidlingren in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

davidlingren Security Vulnerabilities & Risk Score | 19 CVEs | SecAlerts - SecAlerts