CVE-2026-34885 is an SQL injection vulnerability in David Lingren's Media Library Assistant affecting versions 3.34 and earlier. The flaw allows improper neutralization of special elements in SQL commands, enabling attackers to execute arbitrary SQL queries against the application's database. The vulnerability carries a CVSS score of 8.5 (HIGH) and requires network access with low complexity and valid user credentials to exploit. While confidentiality impact is high, the attack carries limited integrity risk and low availability impact. The broader scope of the vulnerability suggests potential lateral movement or multi-system compromise possibilities. There is no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat tracking lists. However, with a FAUCET Risk Score of 53/100 and an EPSS score indicating higher prevalence than the majority of CVEs, organizations should prioritize patching authenticated users and monitoring for suspicious SQL-based activities. Immediate remediation is recommended given the authentication requirement presents a realistic attack scenario for insider threats or compromised user accounts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.34CPE match | cpe:2.3:a:davidlingren:media_library_assistant:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.