All verified exploits

CVE-2025-12707 Library Management System SQL Injection

Deterministic high WordPress Added cve-verified-cve-2025-12707

Detects the Library Management System WordPress plugin at version 3.2.1 or earlier, where the bid parameter in the book shortcode handler has insufficient escaping, allowing unauthenticated attackers to inject SQL and extract sensitive data from the database.

Related WordPress exploits

Is your app exploitable through CVE-2025-12707?

Scan your domain free