nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-11732 CVE-2020-11732
HIGHNuclei
Media Library Assistant plugin before 2.82 for Wordpress Local File Inclusion Vulnerability
Record summary
CVE-2020-11732 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 12, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
media_library_assistantBrowse davidlingren / media_library_assistant | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHMedia Library Assistant < 2.82 - Unauthenticated Limited Local File InclusionCVSS 7.5
Media Library Assistant plugin for WordPress before 2.82 contains a local file inclusion caused by unsanitized mla_gallery link parameter, letting attackers include arbitrary local files, exploit requires access to the vulnerable link.
Impact
Attackers can include arbitrary local files, potentially leading to information disclosure or code execution.
Remediation
Update to version 2.82 or later.
AuthorsSourabh-Sahu
Template tagswpscancvecve2020wordpresswpwp-pluginmedia-library-assistantunauthvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:davidlingren:media_library_assistant:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"wp-content/plugins/media-library-assistant"
FOFA: body="wp-content/plugins/media-library-assistant"
Source: ProjectDiscovery
References
2wordpress.org
https://wordpress.org/plugins/media-library-assistant