cleantalk
Vulnerabilities and Security Researches

Media Library Assistant, CVE-2020-11928

CVE, Research URL

CVE-2020-11928

Published on
Apr 20, 2020
Research Description
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
Affected versions
Min -, max 2.82.
Status
vulnerable