Sceawere

Vulnerability Detail

CVE-2026-32581UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Mooberry Book Manager SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
mooberrydreams
Product
Mooberry Book Manager
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:43.930Z",
  "pubdate": "2026-10-06T09:17:43.930Z",
  "executiveSummary": "Mooberry Book Manager version 4.16.2 is susceptible to an authenticated SQL injection vulnerability.\nThis vulnerability originates from the improper sanitization of user-supplied input before being included in SQL queries, allowing an attacker with subscriber-level privileges to interact directly with the underlying database.\nThe security impact is critical, as successful exploitation enables unauthorized data retrieval, modification, or deletion, potentially leading to full compromise of the database contents.\nAn attacker requires authenticated access to the target WordPress instance with at least subscriber-level permissions to trigger the vulnerability.\nThe risk implication is severe, as the application fails to enforce secure input handling, granting low-privileged users the capability to execute arbitrary SQL commands.\nThere are no specific requirements for external network exposure beyond the ability to reach the administrative or front-end interface where the vulnerable input parameter is processed.",
  "technicalDetails": "The vulnerability resides within the Mooberry Book Manager plugin, specifically in the handling of user-supplied data transmitted via parameters that are subsequently passed to database queries.\nThe root cause is the lack of proper input validation and the absence of parameterized queries or prepared statements when constructing dynamic SQL statements using unsanitized input.\nIn Mooberry Book Manager 4.16.2, specific functions responsible for processing book management or metadata retrieval fail to treat incoming data as untrusted, thereby permitting the injection of malicious SQL syntax into the database engine.\nThe attack flow begins when an authenticated user with subscriber-level access crafts an HTTP request containing a manipulated parameter. This payload is then processed by the vulnerable component of the plugin.\nBecause the input is concatenated directly into the query string, the database engine interprets the injected SQL commands as part of the intended query, rather than literal data.\nAn attacker can exploit this by injecting Union-based SQL injection techniques to extract sensitive information from other tables within the WordPress database, such as the wp_users table, which contains password hashes and administrative credentials.\nFurthermore, depending on the database user permissions, the attacker may be able to execute blind SQL injection attacks to infer data bit-by-bit or, in misconfigured environments, perform data modification or destructive actions via stacked queries if the underlying database driver supports them.\nThe vulnerability is accessible to any user authenticated with a role of subscriber or higher. The exploitation does not require advanced technical bypasses, as the flaw lies in the fundamental design of the query construction logic within the plugin's codebase.\nPost-exploitation, an attacker can escalate their impact by obtaining credentials to higher-privileged accounts, modifying plugin settings to inject malicious scripts into the front-end, or potentially achieving remote code execution if the database environment allows for functions like 'INTO OUTFILE' or similar capabilities to write to the web directory."
}
CVE-2026-32581: Mooberry Book Manager SQL Injection (HIGH Severity, CVSS: 7.1) | Sceawere