CVE-2025-63065: WordPress Media LIbrary Assistant plugin <= 3.29 - Broken Access Control vulnerability
Published Dec 9, 2025
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media LIbrary Assistant: from n/a through <= 3.29.
Affected Software
1 affected component
David Lingren Media Library Assistant<=3.29
Remediation
Information
Update the WordPress Media LIbrary Assistant plugin to the latest available version (at least 3.30).
Event History
Dec 9, 2025
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-63065?
The severity of CVE-2025-63065 is classified as high due to its potential for unauthorized access.
2
How do I fix CVE-2025-63065?
To fix CVE-2025-63065, update Media Library Assistant to version 3.31 or later.
3
What does CVE-2025-63065 affect?
CVE-2025-63065 affects Media Library Assistant versions from n/a through 3.30.
4
What type of vulnerability is CVE-2025-63065?
CVE-2025-63065 is an Authorization Bypass vulnerability due to incorrectly configured access control security levels.
5
Who is the vendor for CVE-2025-63065?
The vendor for CVE-2025-63065 is David Lingren, the creator of the Media Library Assistant plugin.