CVE-2026-24977: WordPress Organici Library plugin <= 2.1.2 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library allows Blind SQL Injection.This issue affects Organici Library: from n/a through <= 2.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24977?
CVE-2026-24977 is a critical security vulnerability that allows for Blind SQL Injection in the NooTheme Organici Library plugin.
How do I fix CVE-2026-24977?
To fix CVE-2026-24977, upgrade the NooTheme Organici Library plugin to version 2.1.3 or later.
What is affected by CVE-2026-24977?
CVE-2026-24977 affects NooTheme Organici Library plugin versions up to and including 2.1.2.
What are the potential impacts of CVE-2026-24977?
The impact of CVE-2026-24977 includes unauthorized access to the database, allowing attackers to read and manipulate data.
Who is the vendor for CVE-2026-24977?
The vendor for CVE-2026-24977 is NooTheme, the developer of the Organici Library plugin.