CVE Database /
CVE-2024-6823
CVE · High
CVE-2024-6823 — Media Library Assistant [media-library-assistant] < 3.19
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-6823
|
Media Library Assistant [media-library-assistant] < 3.19 |
Unrestricted Upload of File with Dangerous Type |
High
8.8
|
< 3.19
|
3.19 |
2024-08-12 |
—
|
CVE-2024-6823
The Media Library Assistant plugin for WordPress contains a security flaw that allows authorized users with at least Author privileges to bypass file type restrictions when uploading files via the mla-inline-edit-upload-scripts AJAX action in versions prior to 3.19, potentially leading to unauthorized file uploads and subsequent remote code execution on the server. This vulnerability affects all plugin versions up to and including 3.18.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings