Description
WordPress Plugin Media Library Assistant is prone to multiple vulnerabilities, including arbitrary file deletion and arbitrary file download vulnerabilities. An attacker can exploit these vulnerabilities to delete arbitrary files or to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Media Library Assistant version 2.65 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.70 or latest
References
Related Vulnerabilities
WordPress Plugin WP TFeed includes Backdoor [Only if downloaded via the vendor website] (1.6.7)
WordPress Plugin MainWP Child Reports SQL Injection (2.0.7)
WordPress Plugin WP Hotel Booking PHP Object Injection (1.10.3)
Envoy Proxy Out-of-bounds Write Vulnerability (CVE-2019-18801)
WordPress Plugin WP Real Estate Unspecified Vulnerability (2.0)