plugin

Library Management System Vulnerabilities

11 known security issues reported for the Library Management System WordPress plugin. Most recent disclosed Aug 5, 2026.

3 high 4 medium

Running Library Management System on your site? Check whether your installed version is affected.

Scan your site free

Library Management System <= 3.6.6 - Authenticated (Subscriber+) SQL Injection

medium

The Library Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level ac...

CVSS:
6.5
Affected:
up to 3.6.6
Fixed in:
3.6.7
Disclosed:
Aug 5, 2026

CVE-2026-18666 on NVD →

Library Management System <= 3.5.7 - Unauthenticated SQL Injection

high

The Library Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQ...

CVSS:
7.5
Affected:
up to 3.5.7
Fixed in:
3.5.8
Disclosed:
Jun 23, 2026

CVE-2026-56034 on NVD →

Library Management System <= 3.5.7 - Unauthenticated SQL Injection

high

The Library Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQ...

CVSS:
7.5
Affected:
up to 3.5.7
Fixed in:
3.5.8
Disclosed:
Jun 22, 2026

CVE-2026-12582 on NVD →

Library Management System [library-management-system] < 3.3

unknown

[en] The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...

Affected:
up to 3.3
Fixed in:
3.3
Disclosed:
Feb 19, 2026

CVE-2025-12707 on NVD →

Library Management System <= 3.2.1 - Unauthenticated SQL Injection

high

The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated atta...

CVSS:
7.5
Affected:
up to 3.2.1
Fixed in:
3.3
Disclosed:
Feb 18, 2026

CVE-2025-12707 on NVD →

Library Management System [library-management-system] <= 3.1 (unfixed + closed)

unknown

[en] The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscriber-level access...

Affected:
up to 3.1
Fix:
No patched version reported
Disclosed:
Oct 15, 2025

CVE-2025-10303 on NVD →

Library Management System <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Settings Manipulation

medium

The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscriber-level access and a...

CVSS:
4.3
Affected:
up to 3.1
Fixed in:
3.2
Disclosed:
Oct 14, 2025

CVE-2025-10303 on NVD →

Library Management System [library-management-system] <= 3.0.0 (unfixed + closed)

unknown

[en] The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up to, and including, 3.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...

Affected:
up to 3.0.0
Fix:
No patched version reported
Disclosed:
Dec 12, 2024

CVE-2024-12406 on NVD →

Library Management System <= 3.2.0 - Authenticated (Subscriber+) SQL Injection

medium

The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query...

CVSS:
6.5
Affected:
up to 3.2.0
Fixed in:
3.2.1
Disclosed:
Dec 11, 2024

CVE-2024-12406 on NVD →

Library Management System [library-management-system] <= 3.0.0 (unfixed + closed)

unknown

[en] The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

Affected:
up to 3.0.0
Fix:
No patched version reported
Disclosed:
Dec 7, 2024

CVE-2024-8679 on NVD →

Library Management System <= 3.1 - Authenticated (Admin+) SQL Injection

medium

The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

CVSS:
6.8
Affected:
up to 3.1
Fixed in:
3.2
Disclosed:
Dec 6, 2024

CVE-2024-8679 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database