Feed/CVE-2026-16959
CVE-2026-16959

CVE-2026-16959

Published Aug 21, 2026·Updated Aug 21, 2026

NVD Description

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free