Impact
The Library Management System plugin for WordPress allows an attacker to manipulate the 'bid' query string parameter without proper sanitization or query preparation. This flaw permits the injection of arbitrary SQL code into existing database queries, enabling the extraction or modification of sensitive data stored in the WordPress database. The attack does not require authentication, meaning any entity with network access to the site can exploit the vulnerability and potentially compromise confidentiality and integrity of the database contents.
Affected Systems
OWTHUB’s Library Management System plugin, all releases up to and including version 3.2.1, is affected. The vulnerability exists in the WordPress plugin version as delivered under the owthub:Library Management System name, and any site running these releases is at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium-to-high severity vulnerability that can lead to significant data exposure. The EPSS score of less than 1% suggests that the likelihood of a publicly exploited attack is low at present, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw allows unauthenticated injection, the attack vector is likely a simple HTTP request containing a crafted 'bid' parameter, and attackers who discover it could gain full read or change access to the database wherever the plugin is installed.
OpenCVE Enrichment