CVE · High

CVE-2026-6075 — Media Library Assistant [media-library-assistant] < 3.36

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6075 Media Library Assistant [media-library-assistant] < 3.36 Cross-Site Request Forgery (CSRF) High 8.1 < 3.36 3.36 2026-05-28

CVE-2026-6075

The Media Library Assistant WordPress plugin has a security flaw that allows unauthorized access to certain actions within its settings. Specifically, the plugin fails to properly verify user authentication for bulk action handlers in the settings tab, which can be exploited by malicious actors to manipulate plugin settings or attachment information without legitimate administrator consent. This vulnerability affects versions up to 3.35 of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.