← Back to browse · API

CVE-2023-4634

Severity
CRITICAL
CVSS
9.8
EPSS
0.82585
Risk score
68.1
CISA KEV
No
PoC
No
Published
2023-09-06
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2023-54487, GHSA-8MV6-Q53Q-HQJ8
Products
David Lingren:Media Library Assistant 0 ≤3.09
Sources
euvd EUVD-2023-54487

Description

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.

References