CVE-2025-31627: WordPress Media Library Assistant plugin <= 3.24 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through <= 3.24.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31627?
CVE-2025-31627 is classified as a Stored Cross-Site Scripting (XSS) vulnerability, which can lead to serious security risks such as data theft and compromise.
How do I fix CVE-2025-31627?
To fix CVE-2025-31627, upgrade the Media Library Assistant plugin to version 3.25 or higher, which addresses the identified vulnerability.
What versions are affected by CVE-2025-31627?
CVE-2025-31627 affects all versions from n/a to 3.24 of the Media Library Assistant plugin.
What is Stored Cross-Site Scripting as seen in CVE-2025-31627?
Stored Cross-Site Scripting is a vulnerability where attackers can inject malicious scripts that are stored on the server and executed when users access the affected web pages.
Who is impacted by CVE-2025-31627?
Users of the Media Library Assistant plugin for WordPress versions up to 3.24 are primarily impacted by CVE-2025-31627.