CVE Database /
CVE-2026-6075
CVE · High
CVE-2026-6075 — Media Library Assistant [media-library-assistant] < 3.36
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-6075
|
Media Library Assistant [media-library-assistant] < 3.36 |
Cross-Site Request Forgery (CSRF) |
High
8.1
|
< 3.36
|
3.36 |
2026-05-28 |
—
|
CVE-2026-6075
The Media Library Assistant WordPress plugin has a security flaw that allows unauthorized access to certain actions within its settings. Specifically, the plugin fails to properly verify user authentication for bulk action handlers in the settings tab, which can be exploited by malicious actors to manipulate plugin settings or attachment information without legitimate administrator consent. This vulnerability affects versions up to 3.35 of the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings