CVE-2024-3518: Media Library Assistant <= 3.15 - Authenticated (Contributor+) SQL Injection via Shortcode
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3518?
CVE-2024-3518 has a high severity rating due to its potential for SQL Injection attacks.
How do I fix CVE-2024-3518?
To fix CVE-2024-3518, update the Media Library Assistant plugin to version 3.16 or later.
What impact does CVE-2024-3518 have on my WordPress site?
CVE-2024-3518 can allow attackers to execute arbitrary SQL queries, compromising your database.
Is my site affected by CVE-2024-3518?
If you are using Media Library Assistant plugin version 3.15 or lower, your site is vulnerable to CVE-2024-3518.
What should I do if I cannot update to a fixed version for CVE-2024-3518?
If you cannot update, consider disabling the Media Library Assistant plugin until you can secure your site.