WordPress 媒体库助手(Media Library Assistant)插件在 3.35 及更早版本中,通过批量编辑预设(preset)的导出/导入机制存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。其成因在于 函数和 模板中,预设字段值在渲染为 HTML 属性上下文时缺乏充分的输出转义。 虽然对于不具备 能力的用户,预设导出时会应用 过滤,但由于恶意载荷由引号和 HTML 属性组成,而非 HTML 标签,因此无法阻止属性注入攻击。 当预设值被读取并渲染时,它们会
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dglingren | Media Library Assistant | 0 ~ 3.35 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6641 | 6.4 MEDIUM | Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting |
| CVE-2026-6640 | 6.4 MEDIUM | Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting |
No comments yet