PLUGIN SECURITY
Is Media Library Assistant safe?
Enhances the Media Library; powerful gallery and list shortcodes, full taxonomy support, IPTC/EXIF/XMP/PDF processing, bulk/quick edit.
What this plugin does
- Slug:
media-library-assistant - Author: David Lingren
- 70000+ active installs
- 96/100 rating (201 reviews on wordpress.org)
- 2776090 all-time downloads
- On WordPress.org since 2012-08-13
categoriesimagesmediamedia librarytags
Maintenance status
- Latest known version: 3.39
- Last updated: 2026-08-17 9:33pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
37 known CVEs on file for Media Library Assistant.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-16959 | Media Library Assistant [media-library-assistant] < 3.40 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Unknown | < 3.40 | 3.40 | 2026-08-21 | ⚠ update needed |
| CVE-2026-66601 | Media Library Assistant [media-library-assistant] < 3.40 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.40 | 3.40 | 2026-08-20 | ⚠ update needed |
| CVE-2026-66600 | Media Library Assistant [media-library-assistant] < 3.40 | Unrestricted Upload of File with Dangerous Type | Critical 9.1 | < 3.40 | 3.40 | 2026-08-20 | ⚠ update needed |
| CVE-2026-66591 | Media Library Assistant [media-library-assistant] < 3.40 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.40 | 3.40 | 2026-08-18 | ⚠ update needed |
| CVE-2026-61963 | Media Library Assistant [media-library-assistant] < 3.39 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.39 | 3.39 | 2026-08-04 | ✓ fixed in latest |
| CVE-2026-56012 | Media Library Assistant [media-library-assistant] < 3.36 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.5 | < 3.36 | 3.36 | 2026-06-18 | ✓ fixed in latest |
| CVE-2026-54198 | Media Library Assistant [media-library-assistant] < 3.36 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.36 | 3.36 | 2026-06-15 | ✓ fixed in latest |
| CVE-2026-6075 | Media Library Assistant [media-library-assistant] < 3.36 | Cross-Site Request Forgery (CSRF) | High 8.1 | < 3.36 | 3.36 | 2026-05-28 | ✓ fixed in latest |
+ 36 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-34897 | Media Library Assistant [media-library-assistant] < 3.35 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.35 | 3.35 | 2026-04-06 | ✓ fixed in latest |
| CVE-2026-34885 | Media Library Assistant [media-library-assistant] < 3.35 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.5 | < 3.35 | 3.35 | 2026-04-06 | ✓ fixed in latest |
| CVE-2026-32399 | Media Library Assistant [media-library-assistant] < 3.33 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.5 | < 3.33 | 3.33 | 2026-02-20 | ✓ fixed in latest |
| CVE-2025-11738 | Media Library Assistant [media-library-assistant] < 3.30 | External Control of File Name or Path | Medium 5.3 | < 3.30 | 3.30 | 2025-10-17 | ✓ fixed in latest |
| CVE-2025-63065 | Media Library Assistant [media-library-assistant] < 3.30 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 3.30 | 3.30 | 2025-10-09 | ✓ fixed in latest |
| CVE-2025-31627 | Media Library Assistant [media-library-assistant] < 3.25 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 3.25 | 3.25 | 2025-03-31 | ✓ fixed in latest |
| CVE-2024-11974 | Media Library Assistant [media-library-assistant] < 3.24 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.24 | 3.24 | 2025-01-03 | ✓ fixed in latest |
| CVE-2024-51661 | Media Library Assistant [media-library-assistant] < 3.20 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Critical 9.1 | < 3.20 | 3.20 | 2024-11-01 | ✓ fixed in latest |
| CVE-2024-6823 | Media Library Assistant [media-library-assistant] < 3.19 | Unrestricted Upload of File with Dangerous Type | High 8.8 | < 3.19 | 3.19 | 2024-08-12 | ✓ fixed in latest |
| CVE-2024-5544 | Media Library Assistant [media-library-assistant] < 3.18 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.18 | 3.18 | 2024-07-01 | ✓ fixed in latest |
| CVE-2024-5605 | Media Library Assistant [media-library-assistant] < 3.17 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 3.17 | 3.17 | 2024-06-19 | ✓ fixed in latest |
| CVE-2024-3519 | Media Library Assistant [media-library-assistant] < 3.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.16 | 3.16 | 2024-05-21 | ✓ fixed in latest |
| CVE-2024-3518 | Media Library Assistant [media-library-assistant] < 3.16 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 3.16 | 3.16 | 2024-05-21 | ✓ fixed in latest |
| CVE-2024-2475 | Media Library Assistant [media-library-assistant] < 3.14 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.14 | 3.14 | 2024-03-28 | ✓ fixed in latest |
| CVE-2024-2871 | Media Library Assistant [media-library-assistant] < 3.14 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.7 | < 3.14 | 3.14 | 2024-03-25 | ✓ fixed in latest |
| CVE-2023-24385 | Media Library Assistant [media-library-assistant] < 3.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 3.12 | 3.12 | 2023-10-02 | ✓ fixed in latest |
| CVE-2023-4716 | Media Library Assistant [media-library-assistant] < 3.11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.11 | 3.11 | 2023-09-21 | ✓ fixed in latest |
| CVE-2023-4634 | Media Library Assistant [media-library-assistant] < 3.10 | External Control of File Name or Path | Critical 9.8 | < 3.10 | 3.10 | 2023-09-05 | ✓ fixed in latest |
| CVE-2023-34010 | Media Library Assistant [media-library-assistant] < 3.0.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.8 | < 3.08 | 3.08 | 2023-07-12 | ✓ fixed in latest |
| CVE-2023-0279 | Media Library Assistant [media-library-assistant] < 3.06 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.2 | < 3.06 | 3.06 | 2023-02-16 | ✓ fixed in latest |
| CVE-2022-41618 | Media Library Assistant [media-library-assistant] < 3.01 | Exposure of Sensitive Information to an Unauthorized Actor | Low 3.7 | < 3.01 | 3.01 | 2022-09-29 | ✓ fixed in latest |
| — | Media Library Assistant [media-library-assistant] < 2.9.0 | — | Unknown | < 2.9.0 | 2.9.0 | 2020-11-24 | ✓ fixed in latest |
| CVE-2020-11928 | Media Library Assistant [media-library-assistant] < 2.82 | — | Critical 9.8 | < 2.82 | 2.82 | 2019-12-15 | ✓ fixed in latest |
| CVE-2020-11731 | Media Library Assistant [media-library-assistant] < 2.82 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.82 | 2.82 | 2019-12-15 | ✓ fixed in latest |
| CVE-2020-11732 | Media Library Assistant [media-library-assistant] < 2.82 | — | High 7.5 | < 2.82 | 2.82 | 2019-12-15 | ✓ fixed in latest |
| CVE-2018-20982 | Media Library Assistant [media-library-assistant] < 2.74 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.74 | 2.74 | 2018-05-28 | ✓ fixed in latest |
| — | Media Library Assistant [media-library-assistant] < 3.27 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.27 | 3.27 | 0000-00-00 | ✓ fixed in latest |
| — | Media Library Assistant [media-library-assistant] < 3.28 | Missing Authorization | Medium 4.3 | < 3.28 | 3.28 | 0000-00-00 | ✓ fixed in latest |
| — | Media Library Assistant [media-library-assistant] < 3.34 | — | Unknown | < 3.34 | 3.34 | 0000-00-00 | ✓ fixed in latest |
| — | Media Library Assistant [media-library-assistant] < 3.29 | — | Medium 5.9 | < 3.29 | 3.29 | 0000-00-00 | ✓ fixed in latest |
| — | Media Library Assistant [media-library-assistant] < 2.90 | — | Unknown | < 2.90 | 2.90 | — | ✓ fixed in latest |
| — | Media Library Assistant < 2.90 - Authenticated Blind SQL Injection | — | Unknown | < 2.90 | 2.90 | — | ✓ fixed in latest |
| CVE-2025-7035 | Media Library Assistant < 3.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes | — | Unknown | < 3.27 | 3.27 | — | ✓ fixed in latest |
| CVE-2025-8357 | Media Library Assistant < 3.28 - Authenticated (Author+) Limited File Deletion | — | Unknown | < 3.28 | 3.28 | — | ✓ fixed in latest |
| CVE-2025-59590 | Media Library Assistant < 3.29 - Authenticated (Author+) Stored Cross-Site Scripting | — | Unknown | < 3.29 | 3.29 | — | ✓ fixed in latest |
| CVE-2026-3072 | Media Library Assistant < 3.34 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification | — | Unknown | < 3.34 | 3.34 | — | ✓ fixed in latest |
How to fix it
Keep Media Library Assistant updated — 3.39 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Autoptimize — 800000+ active installs — 94/100 (1428) — max PHP 8.4
- WebP Express — 300000+ active installs — 88/100 (161) — max PHP 8.4
- Responsive Lightbox & Gallery — 100000+ active installs — 98/100 (1999) — max PHP 8.4
- Modern Image Formats — 100000+ active installs — 70/100 (25)
- Lightbox & Modal Popup WordPress Plugin – FooBox — 100000+ active installs — 78/100 (95) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.