What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.19.
Explanation of Vulnerability in Simple Terms
02Summary
Media Library Assistant versions 3.19 and earlier contain an OS command injection vulnerability. An authenticated administrator can inject arbitrary shell commands through the plugin's file handling functions. The injected commands execute with the web server's privileges, potentially allowing full site compromise. Update to a version newer than 3.19 immediately.
What an attacker can do
03Attacker Capabilities
Run arbitrary shell commands on the server with web server privileges.
Potential impact on your site
04Site Impact
A compromised admin account can execute system commands, read files, modify site data, or install backdoors.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the WordPress site.
Key dates
06Disclosure timeline
November 4, 2024
CVE published
May 11, 2026
Record updated