Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owthub
Owthub library Management System Wordpress Wordpress wordpress |
|
| Vendors & Products |
Owthub
Owthub library Management System Wordpress Wordpress wordpress |
Wed, 15 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update and manipulate several of the plugin's settings and features. | |
| Title | Library Management System <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Settings Manipulation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-10-15T14:23:15.919Z
Reserved: 2025-09-11T21:35:10.838Z
Link: CVE-2025-10303
Updated: 2025-10-15T14:17:14.556Z
Status : Awaiting Analysis
Published: 2025-10-15T09:15:39.780
Modified: 2025-10-16T15:28:59.610
Link: CVE-2025-10303
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:41:13Z