CVE Database /
CVE-2025-11738
CVE · Medium
CVE-2025-11738 — Media Library Assistant [media-library-assistant] < 3.30
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-11738
|
Media Library Assistant [media-library-assistant] < 3.30 |
External Control of File Name or Path |
Medium
5.3
|
< 3.30
|
3.30 |
2025-10-17 |
—
|
CVE-2025-11738
A vulnerability has been discovered in Media Library Assistant plugin versions prior to 3.30 that allows unauthorized users to access and view the contents of certain file types stored on the server, including AI, EPS, PDF, and PS files, potentially exposing sensitive data. This issue arises from a flaw in the mla-stream-image.php file, which can be exploited without requiring authentication.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings