SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16532

CRITICAL · CVSS 9.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Link Library WordPress plugin prior to version 7.9.3 is vulnerable to SQL injection due to inadequate sanitization and escaping of user-supplied input in SQL queries. This critical flaw allows unauthenticated attackers to execute arbitrary SQL commands, potentially compromising the database and exposing sensitive information. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-16532
Severity
CRITICAL
CVSS
9.1
EPSS
0.26%
WordPress

Original NVD Description

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.