CVE Database /
CVE-2026-54198
CVE · High
CVE-2026-54198 — Media Library Assistant [media-library-assistant] < 3.36
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-54198
|
Media Library Assistant [media-library-assistant] < 3.36 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 3.36
|
3.36 |
2026-06-15 |
—
|
CVE-2026-54198
The Media Library Assistant plugin for WordPress has a security flaw that allows attackers to inject malicious code into web pages. This can happen when a user clicks on a link or performs another action, and it doesn't require the attacker to be authenticated. The vulnerability arises from the plugin's failure to properly filter and sanitize user input, making it possible for attackers to inject arbitrary scripts into the page.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings