CVE-2025-11738

The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the server, which can contain sensitive information.
Configurations

No configuration.

History

18 Oct 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-18 06:15

Updated : 2025-10-21 19:31


NVD link : CVE-2025-11738

Mitre link : CVE-2025-11738

CVE.ORG link : CVE-2025-11738


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path