Media Library Assistant plugin for WordPress before 2.82 contains a local file inclusion caused by unsanitized mla_gallery link parameter, letting attackers include arbitrary local files, exploit requires access to the vulnerable link.
id: CVE-2020-11732
info:
name: Media Library Assistant < 2.82 - Unauthenticated Limited Local Fil
...