PT-2025-49896 · WordPress · Media Library Tools

Published

2025-12-09

·

Updated

2025-12-15

·

CVE-2025-67520

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Media Library Tools versions through 1.6.15
Description A flaw exists in Media Library Tools that allows for SQL Injection. This issue is due to improper neutralization of special elements used in an SQL command. The vulnerability could potentially allow an attacker to manipulate database queries.
Recommendations Update Media Library Tools to a version later than 1.6.15.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-67520

Affected Products

Media Library Tools