CVE-2023-4634
The Media Library Assistant plugin for WordPress through version 3.09 contains a local file inclusion and remote code execution vulnerability stemming from inadequate validation of file paths passed to the 'mla_stream_file' parameter in the mla-stream-image.php file. Unauthenticated attackers can exploit this flaw by uploading files through FTP that, when processed by Imagick(), enable directory enumeration, arbitrary file access, and remote code execution. The vulnerability requires no authentication to trigger and affects all installations running version 3.09 or earlier.
Based on public CVE data (MITRE/NVD).