Junglewise Threat Intelligence

CVE-2026-56034: Online Web Tutor Library Management System unauthenticated SQL injection

CVE-2026-56034 · Severity: critical · CVSS 9.3 · Published 2026-06-26

Executive brief

The Library Management System plugin for WordPress is vulnerable to a critical security flaw that allows attackers to access the underlying database without needing a password. This plugin is used to manage book inventories and library operations on websites. An exploit could allow an attacker to steal sensitive information, modify library records, or disrupt site operations.

Technical details

An unauthenticated SQL injection vulnerability exists in the Online Web Tutor Library Management System plugin for WordPress through version 3.5.7. The flaw is caused by improper neutralization of special elements used in SQL commands (CWE-89). A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to the application, allowing them to directly interact with the database. This can lead to unauthorized data exfiltration or limited service disruption. The issue is resolved in version 3.5.8.

Affected products

  • Online Web Tutor Library Management System <= 3.5.7

Timeline

  • 2026-03-28: other: Vulnerability reported by researcher
  • 2026-06-23: advisory: Patchstack advisory published
  • 2026-06-26: disclosed: CVE published to NVD dataset

References