CVE · Critical

CVE-2024-51661 — Media Library Assistant [media-library-assistant] < 3.20

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-51661 Media Library Assistant [media-library-assistant] < 3.20 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Critical 9.1 < 3.20 3.20 2024-11-01

CVE-2024-51661

The Media Library Assistant plugin through version 3.19 contains a remote code execution vulnerability that allows attackers to execute arbitrary code on affected systems. The flaw has been resolved in version 3.20 and later. Users of this WordPress plugin should upgrade immediately to eliminate the security risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.