A vulnerability has been found in Library Management System Plugin up to 3.6.6 on WordPress and classified as critical. The affected element is an unknown function. Performing a manipulation results in sql injection.
This vulnerability is reported as CVE-2026-18666. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.