Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34885

41
FAUCET Score

CVE-2026-34885 is an SQL injection vulnerability in David Lingren's Media Library Assistant affecting versions 3.34 and earlier. The flaw allows improper neutralization of special elements in SQL commands, enabling attackers to execute arbitrary SQL queries against the application's database. The vulnerability carries a CVSS score of 8.5 (HIGH) and requires network access with low complexity and valid user credentials to exploit. While confidentiality impact is high, the attack carries limited integrity risk and low availability impact. The broader scope of the vulnerability suggests potential lateral movement or multi-system compromise possibilities. There is no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat tracking lists. However, with a FAUCET Risk Score of 53/100 and an EPSS score indicating higher prevalence than the majority of CVEs, organizations should prioritize patching authenticated users and monitoring for suspicious SQL-based activities. Immediate remediation is recommended given the authentication requirement presents a realistic attack scenario for insider threats or compromised user accounts.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.34CPE match
cpe:2.3:a:davidlingren:media_library_assistant:*:*:*:*:*:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

8.5HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.1
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.67%
Probability of exploitation in next 30 days
EPSS Percentile
74.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-34885 · Apr 8, 2026
This CVE's current EPSS score of 0.0167 is in the 72nd percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

patchstack.com / database/wordpress/plugin/media-library-assistant/vulnerability/wordpress-media-library-assistant-plugin-3-34-sql-injection-vulnerability