What is CVE-2026-61963?
This vulnerability allows unauthenticated Cross-Site Scripting (XSS) in Media Library Assistant plugin versions 3.38 and below. An attacker can inject malicious scripts into the affected website without any authentication. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu zəiflik Media Library Assistant plaginində (versiya 3.38 və aşağı) aşkarlanmış, autentifikasiya olunmamış Cross-Site Scripting (XSS) hücumuna imkan verir. Təcavüzkar istifadəçi girişi olmadan təsirlənən veb-sayta zərərli skript yerləşdirə bilər. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What type of security risk is CVE-2026-61963 in the Media Library Assistant plugin?
CVE-2026-61963 is an unauthenticated Cross-Site Scripting (XSS) vulnerability. This means an attacker can inject malicious scripts into the affected website without any authentication.
What should be done to protect against CVE-2026-61963?
As this vulnerability affects Media Library Assistant plugin versions 3.38 and below, it is recommended to update the plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.