Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via CSV Import
medium
The Tune Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CSV import in all versions up to, and including, 1.6.3. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Subscriber-level access...
- CVSS:
- 6.4
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Feb 5, 2026
CVE-2026-1401 on NVD →
Tune Library [tune-library] < 1.5.5
unknown
[en] SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Sep 7, 2017
CVE-2015-3314 on NVD →
Tune Library < 1.5.5 - SQL Injection
critical
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
- CVSS:
- 9.8
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Apr 20, 2015
CVE-2015-3314 on NVD →
Tune Library [tune-library] < 2.18
unknown
Tune Library plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 2.18
- Fixed in:
- 2.18
- Disclosed:
- Sep 10, 2011
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database