Vulnerability CVE-2024-6823


Published: 2024-08-13

Description:
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

 References:
https://www.wordfence.com/threat-intel/vulnerabilities/id/9a446fe7-c97a-436e-b494-b924e6518297?source=cve
https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-settings.php#L32
https://wordpress.org/plugins/media-library-assistant/#developers
https://plugins.trac.wordpress.org/changeset/3133909/

Copyright 2026, cxsecurity.com

 

Back to Top