CVE Database /
CVE-2023-24385
CVE · Medium
CVE-2023-24385 — Media Library Assistant [media-library-assistant] < 3.12
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-24385
|
Media Library Assistant [media-library-assistant] < 3.12 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.9
|
< 3.12
|
3.12 |
2023-10-02 |
—
|
CVE-2023-24385
The Media Library Assistant plugin versions before 3.12 contain a cross-site scripting vulnerability that could permit attackers to insert harmful code into a website, which would execute when visitors access the site. The injected scripts might include redirects, malicious advertisements, or other HTML content. The vendor has declined to address this issue, and no patched version has been released to resolve the flaw.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings