QID 150726
Date Published: 2023-10-11
QID 150726: WordPress Media Library Assistant Plugin: Remote Code Execution Vulnerability (CVE-2023-4634)
Media Library Assistant is a back-end plugin that helps to organise and manage media files on WordPress.
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.
Affected versions:
The Media Library Assistant plugin prior to 3.10
QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a plugin running on the target application.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the target system.
CVEs related to QID 150726
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Media Library Assistant |
|
||
| Media Library Assistant |
|