Impact
This vulnerability exists in the Library Management System WordPress plugin before version 3.6.7. The plugin fails to sanitize or escape a user‑supplied parameter that is directly inserted into a SQL statement. As a result, users assigned the role of Subscriber can inject arbitrary SQL code. The attacker can retrieve any data stored in the database, including password hashes, potentially facilitating further compromise of the site.
Affected Systems
The affected product is the Library Management System WordPress plugin, versions prior to 3.6.7. No specific vendor information beyond the open‑source nature of the plugin is provided. Site administrators should verify whether their installations are running a vulnerable version of the plugin.
Risk and Exploitability
The flaw is exploitable by users with the low privilege level of Subscriber, typically accorded to ordinary site visitors. While an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the nature of the flaw indicates a high potential for misuse, especially on sites where Subscriber access is widely granted. An attacker only needs to supply a crafted filter value through the plugin’s interface or via a crafted URL, allowing remote database compromise without additional network privileges.
OpenCVE Enrichment