CVE-2026-56012: WordPress Media LIbrary Assistant plugin <= 3.35 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection.
This issue affects Media LIbrary Assistant: from n/a through 3.35.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/media-library-assistantto a version that resolves this vulnerability.Fixed in 3.36
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56012?
The severity of CVE-2026-56012 is rated high with a score of 8.5.
How do I fix CVE-2026-56012?
You can fix CVE-2026-56012 by updating the Media Library Assistant plugin to version 3.36 or later.
What type of vulnerability is CVE-2026-56012?
CVE-2026-56012 is an SQL Injection vulnerability affecting the Media Library Assistant plugin.
What versions are affected by CVE-2026-56012?
CVE-2026-56012 affects media library assistant versions from n/a through 3.35.
What impact does CVE-2026-56012 have on security?
CVE-2026-56012 allows for Blind SQL Injection, which can lead to unauthorized data access.