CVE-2026-6642
Last modified
CVE-2026-6642 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the mla_generate_bulk_edit_form_fieldsets() function and mla-bulk-edit-fieldsets.tpl template. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the mla_generate_bulk_edit_form_fieldsets() function and mla-bulk-edit-fieldsets.tpl template. While wp_kses() filtering is applied during preset export for users without unfiltered_html capability, this does not prevent attribute injection attacks since the malicious payload consists of quotes and HTML attributes rather than HTML tags. When preset values are retrieved and rendered, they are directly assigned to template variables without esc_attr() escaping and then inserted into input element value attributes via simple string replacement. This makes it possible for authenticated attackers, with Author-level access and above (upload_files capability), to inject arbitrary web scripts that execute when an administrator imports the poisoned preset and the targeted input field receives focus.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| dglingren | Media Library Assistant | <= 3.35 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-6642?
How severe is CVE-2026-6642?
How do I fix CVE-2026-6642?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66411DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement aut…5.3
- CVE-2026-66412Leantime 3.6.2 and prior contains a broken access control vu…7.1
- CVE-2026-66414Leantime 3.6.2 contains an open redirect vulnerability in th…6.1
- CVE-2026-66415Leantime 3.6.2 contains a server-side request forgery and lo…8.5
- CVE-2026-66416Leantime 3.6.2 contains a cross-site request forgery vulnera…8.8
- CVE-2026-66418OpenClaw Dashboard v3.0.0 contains a stored cross-site scrip…9.3
- CVE-2026-66420MeshCentral 1.1.21 contains a cross-site WebSocket hijacking…8.8
- CVE-2026-66421OpenClaw Dashboard contains a stored cross-site scripting vu…9.3
- CVE-2026-66422Improper Authorization vulnerability in Apache Tomcat cause …8.1
- CVE-2026-66424Unauthenticated Privilege Escalation in SMS Alert Order Noti…9.8
- CVE-2026-66425Unauthenticated Broken Authentication in Gutena Forms – Cont…6.5
- CVE-2026-66426Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.…7.1
Are you affected by CVE-2026-6642?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
