
Medialist Security & Risk Analysis
wordpress.org/plugins/media-listOrganised lists. Items are displayed elegantly styled on a page. Ideal for displaying policies, documents, newsletters, media, posts and more.
Is Medialist Safe to Use in 2026?
Generally Safe
Score 99/100Medialist has a strong security track record. Known vulnerabilities have been patched promptly.
The media-list plugin v1.5.0 demonstrates several positive security practices, including 100% proper output escaping and the exclusive use of prepared statements for SQL queries. The static analysis also indicates a limited attack surface with only one shortcode entry point and no unprotected AJAX handlers, REST API routes, or cron events. Taint analysis found no critical or high severity issues, suggesting a good initial posture regarding input sanitization and data flow security.
However, the plugin's vulnerability history is a significant concern. With a total of two known medium severity CVEs, both historically related to Cross-site Scripting (XSS), and the most recent one being November 3, 2023, it indicates past weaknesses in handling user-supplied data. While there are currently no unpatched vulnerabilities, the recurrence of XSS suggests a need for more robust input validation and sanitization measures, especially within shortcode processing, which is the plugin's sole identified entry point.
In conclusion, while the current code analysis shows good security hygiene in certain areas, the past vulnerability history, particularly XSS, warrants caution. The plugin has strengths in its implementation of prepared statements and output escaping, but the historical pattern of XSS vulnerabilities highlights a persistent risk area that requires careful attention and potential remediation. The lack of explicit capability checks or nonce checks on its single entry point could also be a potential oversight depending on the shortcode's functionality.
Key Concerns
- 2 known medium severity CVEs
- Last vulnerability was recent (2023-11-03)
- No nonce checks on entry points
- No capability checks on entry points
Medialist Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Medialist <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Medialist <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
Medialist Code Analysis
Output Escaping
Medialist Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Medialist Maintenance & Trust
Maintenance Signals
Community Trust
Medialist Alternatives
Export media with selected content (by DKZR)
export-media-with-selected-content
Include all relevant attachments in your export.
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX
ultimate-post
A highly customizable plugin to create news, magazines, and any kind of blog site with post grid, post filter, post slider, and post blocks.
File Upload Types by WPForms
file-upload-types
Easily allow WordPress to accept and upload any file type extension or MIME type, including custom file types.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters
advanced-post-block
Advanced Post Block lets you add dynamic post grids, lists, sliders, and tickers. Filter content by category, tag, author, or custom post type.
Medialist Developer Profile
1 plugin · 900 total installs
How We Detect Medialist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-list/styles/styles.css/wp-content/plugins/media-list/js/medialistpaging.js/wp-content/plugins/media-list/js/medialistpaging.jsmedia-list/styles/styles.css?ver=media-list/js/medialistpaging.js?ver=HTML / DOM Fingerprints
passtojq