AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18666

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Library Management System WordPress plugin prior to version 3.6.7 is vulnerable to SQL injection due to inadequate sanitization of user-supplied input, enabling users with minimal privileges, such as Subscribers, to execute malicious SQL queries. This flaw could lead to unauthorized access to sensitive data, including user password hashes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-18666
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
WordPress

Original NVD Description

The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes.