PT-2025-42295 · WordPress · Library Management System

Published

2025-10-15

·

Updated

2025-10-15

·

CVE-2025-10303

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Library Management System plugin for WordPress versions prior to 3.2
Description The Library Management System plugin for WordPress is susceptible to unauthorized data modification. This is due to a missing capability check within the owt7 library management ajax handler() function. Authenticated attackers possessing Subscriber-level access or higher can update and manipulate the plugin’s settings and features.
Recommendations Update the Library Management System plugin to version 3.2 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10303

Affected Products

Library Management System