CVE-2022-41618 LOW

CVE-2022-41618: WordPress Media Library Assistant plugin <= 3.00 - Unauthenticated Error Log Disclosure vulnerability

Vendor David Lingren
Product Media Library Assistant (WordPress plugin)
Weakness CWE-200 · Info exposure
Published November 18, 2022
Last update April 28, 2026

CVSS base score

3.7/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

Media Library Assistant versions up to 3.00 expose sensitive information through improper access controls. An attacker can retrieve private or restricted media library data without authentication, though exploitation requires specific conditions. Site administrators should update to a version newer than 3.00 to prevent unauthorized information disclosure.

What an attacker can do

03Attacker Capabilities

Read private or restricted media library data without logging in.

Potential impact on your site

04Site Impact

Private media files and metadata may be exposed to unauthenticated visitors.

Conditions required to exploit

05Prerequisites

Network access to the WordPress site; specific conditions must be met to trigger the vulnerability.

Key dates

06Disclosure timeline

November 18, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE