CyberRota Analysis
AI-GeneratedThe Library Management System WordPress plugin prior to version 3.6.7 is vulnerable to SQL injection due to inadequate sanitization of user-supplied input, enabling users with minimal privileges, such as Subscribers, to execute malicious SQL queries. This flaw could lead to unauthorized access to sensitive data, including user password hashes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes.