
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12707 is an unauthenticated SQL Injection vulnerability in the Library Management System plugin for WordPress, affecting all versions up to and including 3.2.1. The flaw exists in the bid parameter due to insufficient escaping of user-supplied input and lack of proper SQL query preparation, allowing attackers to append malicious SQL queries and extract sensitive data from the database. It was published on February 19, 2026, with a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Wordfence).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), stemming from the plugin's failure to properly escape the bid parameter before incorporating it into SQL queries. Because no prepared statements or parameterized queries are used, an unauthenticated attacker can craft HTTP requests that append additional SQL logic to existing queries — enabling blind or error-based SQL injection techniques. No authentication or special privileges are required, and the attack is conducted entirely over the network with low complexity (Red Hat CVE, Infinit Sec).
Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database, including user credentials, email addresses, session tokens, and other confidential data stored by the application. The confidentiality impact is rated High, while integrity and availability are unaffected by this specific vulnerability. Compromised credentials could enable further account takeover or lateral movement within the WordPress environment (Red Hat CVE, Wordfence).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. The EPSS score is approximately 0.068%, indicating a relatively low but non-negligible probability of exploitation in the near term. Nuclei templates for automated detection have been submitted to the ProjectDiscovery repository, suggesting tooling for mass scanning may be available (ProjectDiscovery, ProjectDiscovery). No confirmed in-the-wild exploitation or CISA KEV listing has been reported at this time.
bid parameter (e.g., a book detail or borrowing page).bid parameter — for example, bid=1 AND 1=2 UNION SELECT user_login,user_pass,3,4 FROM wp_users-- — to extract WordPress user credentials.', --, UNION, SELECT, AND 1=) in the bid parameter; high-frequency requests from a single IP to plugin pages.bid query parameter; repeated 200 responses to plugin endpoints from unfamiliar IP addresses.wp_users or other sensitive tables.Users should update the Library Management System WordPress plugin to a version beyond 3.2.1 that addresses this SQL injection flaw — check the WordPress plugin repository for the latest patched release. If no patch is yet available, consider deactivating and removing the plugin until a fix is released. Additionally, deploying a Web Application Firewall (WAF) such as Wordfence can help detect and block SQL injection attempts targeting this parameter (Wordfence, Red Hat CVE).
Wordfence included CVE-2025-12707 in its weekly WordPress vulnerability report for February 16–22, 2026, highlighting it as a notable unauthenticated SQL injection risk for WordPress site owners (Wordfence). Security community members shared the vulnerability on Mastodon and Bluesky, and Nuclei template pull requests were submitted to ProjectDiscovery's repository for automated detection (ProjectDiscovery). Overall community reaction reflects routine concern about unauthenticated WordPress plugin vulnerabilities, with no extraordinary media coverage noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."