Library Management System WordPress Plugin Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the Library Management System plugin for WordPress, all versions through 3.1, allowing unauthorized data modification. This issue arises from a lack of capability checks in the 'owt7_library_management_ajax_handler()' function. As a result, authenticated attackers with Subscriber-level access or higher can manipulate various plugin settings and features.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in the plugin's settings and features, potentially allowing attackers to disrupt normal library management operations or misuse the plugin's functionality.

Reproduction

To reproduce this vulnerability, an authenticated user with Subscriber-level access or higher can send a request to the 'admin-ajax.php' endpoint. The request must include the 'owt7_lms_nonce' for verification. Once the nonce is validated, the user can specify parameters to manipulate library management data, such as branches, users, bookcases, or categories, depending on the action requested.

Remediation

No known patch is available for this vulnerability. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Oct 15, 2025, 9:43 AM
Updated: Oct 15, 2025, 9:43 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
0.6
exploitability
6.3
remediation
0.0
relevance
0.7
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.