vendor:
Media Library Assistant
by:
Florent MONTEL
6.1
CVSS
HIGH
Remote Code Execution (RCE) and Local File Inclusion (LFI)
CWE
Product Name: Media Library Assistant
Affected Version From: Version < 3.10
Affected Version To: Version 3.09
Patch Exists: NO
Related CWE: CVE-2023-4634
CPE: a:wordpress:media_library_assistant
Platforms Tested:
2023
Media Library Assistant WordPress Plugin – RCE and LFI
Media Library Assistant Wordpress Plugin in version < 3.10 is affected by an unauthenticated remote reference to Imagick() conversion which allows attacker to perform LFI and RCE depending on the Imagick configuration on the remote server. The affected page is: wp-content/plugins/media-library-assistant/includes/mla-stream-image.php
Mitigation:
Upgrade to version 3.10 or later of the Media Library Assistant Wordpress Plugin.