CVE-2020-11732

HIGH EXPLOITED IN THE WILD NUCLEI

Media Library Assistant <2.82 - Local File Inclusion

Title source: llm

Description

The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.

Nuclei Templates (1)

Media Library Assistant < 2.82 - Unauthenticated Limited Local File Inclusion
HIGHVERIFIEDby Sourabh-Sahu
Shodan: http.html:"wp-content/plugins/media-library-assistant"
FOFA: body="wp-content/plugins/media-library-assistant"

Scores

CVSS v3 7.5
EPSS 0.3478
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2021-04-12
InTheWild.io 2021-04-12
Status published
Products (1)
davidlingren/media_library_assistant < 2.82
Published Apr 13, 2020
Tracked Since Feb 18, 2026