vendor:
Media Library Assistant
by:
Daniel Monzón (stark0de)
7.5
CVSS
HIGH
Local File Inclusion
CWE
Product Name: Media Library Assistant
Affected Version From: 2.81
Affected Version To: 2.81
Patch Exists: YES
Related CWE: CVE-2020-11731, CVE-2020-11732
CPE:
Platforms Tested: Windows 7 x86 SP1
2020
WordPress Plugin Media Library Assistant 2.81 – Local File Inclusion
There is a file inclusion vulnerability in the mla-file-downloader.php file. Visiting the vulnerable URL would lead to disclosure of the contents of options.php. Note that this vulnerability does not require authentication.
Mitigation:
Upgrade to the latest version of the plugin.