CVE-2026-34885: WordPress Media LIbrary Assistant plugin <= 3.34 - SQL Injection vulnerability
Published Apr 6, 2026
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34.
Affected Software
1 affected component
David Lingren Media Library Assistant<=3.34
Remediation
Information
Update the WordPress Media LIbrary Assistant Plugin to the latest available version (at least 3.35).
Event History
Apr 6, 2026
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-34885?
CVE-2026-34885 is considered a critical severity vulnerability due to its potential for SQL Injection attacks.
2
How do I fix CVE-2026-34885?
To fix CVE-2026-34885, upgrade the Media Library Assistant plugin to a version higher than 3.34.
3
What types of attacks can CVE-2026-34885 enable?
CVE-2026-34885 can enable attackers to execute arbitrary SQL queries in the database, leading to data exposure or corruption.
4
Which version of Media Library Assistant is affected by CVE-2026-34885?
Media Library Assistant versions 3.34 and earlier are affected by CVE-2026-34885.
5
Who is the vendor of the software impacted by CVE-2026-34885?
The vendor of the software impacted by CVE-2026-34885 is David Lingren.