SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-16959

MEDIUM · CVSS 6.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Media Library Assistant plugin for WordPress versions prior to 3.40 is vulnerable to SQL injection due to inadequate validation of search parameters in its media-library query handlers. This flaw allows users with the Author role to manipulate SQL queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-16959
Severity
MEDIUM
CVSS
6.8
EPSS
0.23%
WordPress

Original NVD Description

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.