Pricing
Case studies
Login
Start trial
Media LIbrary Assistant
David Lingren
Developer
3.35
Latest version
70,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
27 patched
12 Mitigation rules
Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification vulnerability
<= 3.33
04/03/2026
SQL Injection vulnerability
<= 3.32
20/02/2026
Unauthenticated Limited File Read vulnerability
<= 3.29
18/10/2025
Broken Access Control vulnerability
<= 3.29
09/10/2025
Cross Site Scripting (XSS) Vulnerability
<= 3.28
22/09/2025
Authenticated (Author+) Limited File Deletion vulnerability
<= 3.27
18/08/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes vulnerability
<= 3.26
16/07/2025
Stored Cross Site Scripting (XSS) vulnerability
<= 3.24
31/03/2025
Reflected Cross-Site Scripting vulnerability
<= 3.23
03/01/2025
Remote Code Execution (RCE) vulnerability
<= 3.19
01/11/2024
Authenticated (Author+) Arbitrary File Upload via mla-inline-edit-upload-scripts AJAX Action vulnerability
<= 3.18
13/08/2024
Reflected Cross-Site Scripting vulnerability
<= 3.17
02/07/2024
Authenticated SQL Injection vulnerability
<= 3.16
19/06/2024
Authenticated (Contributor+) SQL Injection via Shortcode vulnerability
<= 3.15
22/05/2024
Reflected Cross-Site Scripting via lang vulnerability
<= 3.15
22/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via mla_gallery Shortcode vulnerability
<= 3.13
29/03/2024
Authenticated (Contributor+) SQL Injection via Shortcode vulnerability
<= 3.13
26/03/2024
Cross Site Scripting (XSS) vulnerability
<= 3.11
02/10/2023
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 3.10
22/09/2023
Unauthenticated Local/Remote File Inclusion and Code Execution vulnerability
<= 3.09
06/09/2023
Reflected Cross Site Scripting (XSS) vulnerability
<= 3.0.7
12/07/2023
Admin+ SQL Injection vulnerability
< 3.06
21/02/2023
Unauthenticated Error Log Disclosure vulnerability
<= 3.00
29/09/2022
Authenticated Blind SQL Injection (SQLi) vulnerability
<= 2.84
24/11/2020
Authenticated Remote Code Execution (RCE) vulnerability
<= 2.81
19/04/2020
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 2.81
13/04/2020
Unauthenticated Limited Local File Inclusion (LFI) vulnerability
<= 2.81
13/04/2020