Vulnerability Description
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Davidlingren | Media Library Assistant | < 2.82 |
References
- https://wordpress.org/plugins/media-library-assistant/#developersProductThird Party Advisory
- https://wordpress.org/plugins/media-library-assistant/#developersProductThird Party Advisory
FAQ
What is CVE-2020-11928?
CVE-2020-11928 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
How severe is CVE-2020-11928?
CVE-2020-11928 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-11928?
Check the references section above for vendor advisories and patch information. Affected products include: Davidlingren Media Library Assistant.