CVE · Medium

CVE-2025-11738 — Media Library Assistant [media-library-assistant] < 3.30

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11738 Media Library Assistant [media-library-assistant] < 3.30 External Control of File Name or Path Medium 5.3 < 3.30 3.30 2025-10-17

CVE-2025-11738

A vulnerability has been discovered in Media Library Assistant plugin versions prior to 3.30 that allows unauthorized users to access and view the contents of certain file types stored on the server, including AI, EPS, PDF, and PS files, potentially exposing sensitive data. This issue arises from a flaw in the mla-stream-image.php file, which can be exploited without requiring authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.