QID 731067

QID 731067: WordPress Plugin Media Library Assistant Remote Code Execution (RCE) Vulnerability

The Media Library Assistant provides several enhancements for managing the Media Library.

CVE-2023-4634: The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. Allowing unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible. Affected Versions: Media Library Assistant prior to 3.10

NOTE:
Exploit will only work if WordPress target is configured with default Imagegick installation/configuration.

QID Detection Logic (Unauthenticated): This unauthenticated detection checks for installed vulnerable version for Media Library Assistant Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary command on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Media Library Assistant Plugin version 3.10 and later to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731067

    Software Advisories
    Advisory ID Software Component Link
    Media Library Assistant Plugin Release Notes URL Logo wordpress.org/plugins/media-library-assistant/#developers