CVE-2026-16959 - Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
CVE ID :CVE-2026-16959
Published : Aug. 21, 2026, 7:16 a.m. | 45 minutes ago
Description :The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 21, 2026, 7:16 a.m. | 45 minutes ago
Description :The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...