Library Management System <= 3.6.6 - Authenticated (Subscriber+) SQL Injection
medium
The Library Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level ac...
- CVSS:
- 6.5
- Affected:
- up to 3.6.6
- Fixed in:
- 3.6.7
- Disclosed:
- Aug 5, 2026
CVE-2026-18666 on NVD →
Library Management System <= 3.5.7 - Unauthenticated SQL Injection
high
The Library Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQ...
- CVSS:
- 7.5
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.8
- Disclosed:
- Jun 23, 2026
CVE-2026-56034 on NVD →
Library Management System <= 3.5.7 - Unauthenticated SQL Injection
high
The Library Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQ...
- CVSS:
- 7.5
- Affected:
- up to 3.5.7
- Fixed in:
- 3.5.8
- Disclosed:
- Jun 22, 2026
CVE-2026-12582 on NVD →
Library Management System [library-management-system] < 3.3
unknown
[en] The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- Feb 19, 2026
CVE-2025-12707 on NVD →
Library Management System <= 3.2.1 - Unauthenticated SQL Injection
high
The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...
- CVSS:
- 7.5
- Affected:
- up to 3.2.1
- Fixed in:
- 3.3
- Disclosed:
- Feb 18, 2026
CVE-2025-12707 on NVD →
Library Management System [library-management-system] <= 3.1 (unfixed + closed)
unknown
[en] The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscriber-level access...
- Affected:
- up to 3.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 15, 2025
CVE-2025-10303 on NVD →
Library Management System <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Settings Manipulation
medium
The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscriber-level access and a...
- CVSS:
- 4.3
- Affected:
- up to 3.1
- Fixed in:
- 3.2
- Disclosed:
- Oct 14, 2025
CVE-2025-10303 on NVD →
Library Management System [library-management-system] <= 3.0.0 (unfixed + closed)
unknown
[en] The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up to, and including, 3.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...
- Affected:
- up to 3.0.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 12, 2024
CVE-2024-12406 on NVD →
Library Management System <= 3.2.0 - Authenticated (Subscriber+) SQL Injection
medium
The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query...
- CVSS:
- 6.5
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.1
- Disclosed:
- Dec 11, 2024
CVE-2024-12406 on NVD →
Library Management System [library-management-system] <= 3.0.0 (unfixed + closed)
unknown
[en] The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...
- Affected:
- up to 3.0.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 7, 2024
CVE-2024-8679 on NVD →
Library Management System <= 3.1 - Authenticated (Admin+) SQL Injection
medium
The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...
- CVSS:
- 6.8
- Affected:
- up to 3.1
- Fixed in:
- 3.2
- Disclosed:
- Dec 6, 2024
CVE-2024-8679 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database