The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into performing bulk delete, edit, or purge operations on plugin settings and attachment metadata via a forged request.
Metrics
Affected Vendors & Products
References
History
Fri, 29 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Davidlingren
Davidlingren media Library Assistant Wordpress Wordpress wordpress |
|
| Vendors & Products |
Davidlingren
Davidlingren media Library Assistant Wordpress Wordpress wordpress |
Fri, 29 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 09:00:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-29T10:05:22.136Z
Reserved: 2026-04-10T14:31:12.134Z
Link: CVE-2026-6075
Updated: 2026-05-29T10:05:16.950Z
Status : Deferred
Published: 2026-05-29T09:16:18.400
Modified: 2026-05-29T13:09:05.450
Link: CVE-2026-6075
No data.
OpenCVE Enrichment
Updated: 2026-05-29T14:30:36Z