The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive information.
References
Configurations
No configuration.
History
18 Oct 2025, 06:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-18 06:15
Updated : 2025-10-21 19:31
NVD link : CVE-2025-11738
Mitre link : CVE-2025-11738
CVE.ORG link : CVE-2025-11738
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
