CVE-2026-97293: WordPress Media LIbrary Assistant plugin <= 3.41 - SQL Injection vulnerability
Published Sep 30, 2026
·Updated
Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
Affected Software
1 affected component
WordPress Media Library Assistant<=3.41
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Media Library Assistantto a version that resolves this vulnerability.Fixed in 3.42
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Contributor-level access. The vulnerability does not require user interaction and can be exploited over the network.
2
What is the likely impact if exploitation succeeds?
The vulnerability can expose highly sensitive information through SQL injection and has scope changed impact. It may also cause limited availability impact, while no integrity impact is indicated.