CVE-2026-66600: WordPress Media LIbrary Assistant plugin <= 3.39 - Arbitrary File Upload vulnerability
Published Aug 20, 2026
·Updated
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
Affected Software
1 affected component
WordPress plugin/Media LIbrary Assistant<=3.39
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Media LIbrary Assistant pluginto a version that resolves this vulnerability.Fixed in 3.40
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user with Author-level privileges can exploit the vulnerability. The attack can be performed remotely and does not require user interaction.
2
What is the impact of successful exploitation?
Successful exploitation allows arbitrary file upload. The reported severity is critical, with potential impact to confidentiality, integrity, and availability.
3
Which plugin versions are affected?
Media Library Assistant versions up to and including 3.39 are affected.