PT-2026-57640 · WordPress · Library Management System

CVE-2026-12582

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Library Management System WordPress plugin versions prior to 3.5.8
Description An issue exists where a user-supplied parameter is not properly sanitized or escaped before being used in a SQL statement. This allows unauthenticated attackers to perform SQL injection, which is a technique used to manipulate database queries, and extract arbitrary data from the database, including user password hashes.
Recommendations Update the Library Management System WordPress plugin to version 3.5.8 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-12582

Affected Products

Library Management System