CyberRota Analysis
AI-GeneratedThe Media Library Assistant plugin for WordPress versions prior to 3.40 is vulnerable to SQL injection due to inadequate validation of search parameters in its media-library query handlers. This flaw allows users with the Author role to manipulate SQL queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.
Original NVD Description
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.