โ† Back to Dashboard

CVE-2026-16959

MEDIUM NVD
CVSS Score
6.8
Severity
MEDIUM
Source
NVD
Published
Aug 21, 2026
Description

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.

View Full Details โ† Back