CVE-2026-97294: WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Media Library Assistantto a version that resolves this vulnerability.Fixed in 3.42
Event History
Frequently Asked Questions
Which installations should be considered affected?
Media Library Assistant versions through 3.41 are identified as affected. The available data does not identify a fixed version.
What access does an attacker need to exploit this issue?
The attacker needs low-level privileges and exploitation requires user interaction. The attack vector is network-based and is rated low complexity.
What is the potential impact if exploitation succeeds?
The vulnerability is rated as having low confidentiality, integrity, and availability impact. Its CVSS vector indicates scope may change beyond the initially affected security authority.