CVE · Critical

CVE-2023-4634 — Media Library Assistant [media-library-assistant] < 3.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-4634 Media Library Assistant [media-library-assistant] < 3.10 External Control of File Name or Path Critical 9.8 < 3.10 3.10 2023-09-05

CVE-2023-4634

The Media Library Assistant plugin for WordPress through version 3.09 contains a local file inclusion and remote code execution vulnerability stemming from inadequate validation of file paths passed to the 'mla_stream_file' parameter in the mla-stream-image.php file. Unauthenticated attackers can exploit this flaw by uploading files through FTP that, when processed by Imagick(), enable directory enumeration, arbitrary file access, and remote code execution. The vulnerability requires no authentication to trigger and affects all installations running version 3.09 or earlier.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.