WordPress 的 Media Library Assistant 插件在 3.35 及更早版本中,由于 短代码存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。其根本原因在于对 参数的输入清洗和输出转义不足:当 设置为 时, 函数会通过 和 处理该参数的值,但未对 URL 进行适当的转义,随后直接将其输出到 属性中,而未应用 。 这使得拥有贡献者(contributor)及以上权限的认证攻击者能够向页面注入任意 Web 脚本,这些脚本将在用户访问被注入的页面时执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dglingren | Media Library Assistant | 0 ~ 3.35 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6642 | 6.4 MEDIUM | Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via |
| CVE-2026-6640 | 6.4 MEDIUM | Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting |
No comments yet