CVE-2020-11928: Critical severity media library assistant vulnerability
Published Apr 19, 2020
·Updated
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the taxquery, metaquery, or datequery parameter in mlagallery via an admin.
Affected Software
1 affected component
Davidlingren Media Library Assistant Wordpress<2.82
Event History
Apr 19, 2020
CVE Published
via MITRE·11:16 PM
Data Sourced
via MITRE·11:16 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-11928.
2
What is the severity of CVE-2020-11928?
The severity of CVE-2020-11928 is critical with a severity value of 9.8.
3
What is affected by CVE-2020-11928?
The media-library-assistant plugin before version 2.82 for WordPress is affected by CVE-2020-11928.
4
How can Remote Code Execution occur in CVE-2020-11928?
Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin in CVE-2020-11928.
5
Is there a fix available for CVE-2020-11928?
Yes, it is recommended to update the media-library-assistant plugin to version 2.82 to fix CVE-2020-11928.