The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive information.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Oct 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Davidlingren
Davidlingren media Library Assistant Wordpress Wordpress wordpress |
|
| Vendors & Products |
Davidlingren
Davidlingren media Library Assistant Wordpress Wordpress wordpress |
Sat, 18 Oct 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive information. | |
| Title | Media Library Assistant <= 3.29 - Unauthenticated Limited File Read | |
| Weaknesses | CWE-73 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-10-18T05:41:55.159Z
Updated: 2025-10-20T18:58:57.946Z
Reserved: 2025-10-14T13:25:58.992Z
Link: CVE-2025-11738
Updated: 2025-10-20T18:58:52.859Z
Status : Awaiting Analysis
Published: 2025-10-18T06:15:37.123
Modified: 2025-10-21T19:31:25.450
Link: CVE-2025-11738
No data.
ReportizFlow