What the vulnerability does
01Description
Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.
Explanation of Vulnerability in Simple Terms
Media Library Assistant versions up to 3.00 expose sensitive information through improper access controls. An attacker can retrieve private or restricted media library data without authentication, though exploitation requires specific conditions. Site administrators should update to a version newer than 3.00 to prevent unauthorized information disclosure.
What an attacker can do
Read private or restricted media library data without logging in.
Potential impact on your site
Private media files and metadata may be exposed to unauthenticated visitors.
Conditions required to exploit
Network access to the WordPress site; specific conditions must be met to trigger the vulnerability.
Key dates
External resources
Related vulnerabilities