Sceawere
Vulnerability Detail
CVE-2026-95609UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Media Library Assistant
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- David Lingren
- Product
- Media LIbrary Assistant
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:43.193Z",
"pubdate": "2026-10-09T10:16:43.193Z",
"executiveSummary": "The Media Library Assistant plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability, affecting versions n/a through 3.41, allows an attacker to inject and store malicious scripts within the application's database.\nWhen a victim, such as an administrator or another user with access to the Media Library, views the affected component, the stored script executes within the context of their browser session.\nThe primary risk involves the unauthorized execution of arbitrary JavaScript, which can be leveraged to hijack user sessions, perform actions on behalf of the victim, or redirect users to malicious sites.\nExploitation generally requires the attacker to be able to influence the data stored by the plugin, potentially requiring specific user privileges depending on the plugin's configuration and access control policies.\nThis represents a significant security risk, as the malicious payload persists until removed from the database, enabling sustained attacks against unsuspecting users.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from the application's failure to adequately sanitize, validate, or encode user-controllable input before rendering it in the browser.\nIn the context of the Media Library Assistant plugin (n/a through 3.41), the flaw exists because the application accepts input that is subsequently saved to the backend database without sufficient context-aware output escaping.\nThe attack flow begins when an attacker identifies an input field or parameter processed by the plugin that does not sanitize inputs for HTML or JavaScript syntax. The attacker submits a specially crafted payload containing malicious script tags (e.g., <script>alert(document.cookie)</script>) or event handlers (e.g., onerror, onload) into the vulnerable input field.\nOnce the input is submitted, the plugin processes and persists this data directly into the database. There is no remediation applied at the data storage layer to strip or neutralize these malicious directives.\nThe payload remains dormant until a victim triggers the display of the data associated with the injected input. When the plugin dynamically generates the web page containing the malicious entry, it embeds the attacker-supplied script directly into the HTML document's Document Object Model (DOM).\nUpon rendering the page, the victim's browser interprets the injected script as legitimate code originating from the trusted domain. Because the script executes within the security context of the victim's session, the attacker gains the ability to access sensitive data, such as session cookies (if not protected by HttpOnly flags), local storage, or CSRF tokens.\nFurthermore, the attacker can leverage the victim's authenticated session to perform unauthorized actions, such as modifying plugin settings, deleting media items, or creating new administrative accounts, effectively bypassing intended authorization controls. This attack is persistent because every user who navigates to the affected page will inadvertently trigger the malicious script, magnifying the scope of the impact."
}