CVE · High

CVE-2026-54198 — Media Library Assistant [media-library-assistant] < 3.36

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-54198 Media Library Assistant [media-library-assistant] < 3.36 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.36 3.36 2026-06-15

CVE-2026-54198

The Media Library Assistant plugin for WordPress has a security flaw that allows attackers to inject malicious code into web pages. This can happen when a user clicks on a link or performs another action, and it doesn't require the attacker to be authenticated. The vulnerability arises from the plugin's failure to properly filter and sanitize user input, making it possible for attackers to inject arbitrary scripts into the page.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.