CVE-2026-32581: WordPress Mooberry Book Manager plugin 4.16.2 - SQL Injection vulnerability
Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The vulnerability is described as subscriber SQL injection, so exploitation requires a WordPress account with Subscriber-level access or equivalent authenticated low-privilege access.
Can it be exploited remotely?
Yes. The CVSS vector lists network attack access (AV:N) and no user interaction requirement (UI:N), indicating an authenticated attacker can target it remotely without another user taking action.
How difficult is exploitation?
The CVSS vector rates attack complexity as high (AC:H). Exploitation is therefore not expected to be straightforward even when the attacker has the required low-privilege account.
What is the potential impact?
Successful exploitation may expose highly sensitive information and cause limited availability impact. The vector indicates scope can change (S:C), while integrity impact is listed as none.