CVE Database /
CVE-2026-6075
CVE · High
CVE-2026-6075 — Media Library Assistant [media-library-assistant] < 3.36
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-6075
|
Media Library Assistant [media-library-assistant] < 3.36 |
Cross-Site Request Forgery (CSRF) |
High
8.1
|
< 3.36
|
3.36 |
2026-05-28 |
—
|
CVE-2026-6075
The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into performing bulk delete, edit, or purge operations on plugin settings and attachment metadata via a forged request.
Source:
CVE.org
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings