Sceawere

Vulnerability Detail

CVE-2026-96822UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated SQL Injection in Books Gallery

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
3h ago
Vendor
Hossni Mubarak
Product
Books Gallery
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-09-30T13:17:31.750Z",
  "pubdate": "2026-09-30T13:17:31.750Z",
  "executiveSummary": "The Books Gallery plugin for WordPress is susceptible to an unauthenticated SQL Injection vulnerability in versions 4.8.3 and below.\nThis vulnerability stems from improper neutralization of special elements used in an SQL command, allowing an unauthenticated remote attacker to manipulate database queries.\nSuccessful exploitation permits unauthorized access to the underlying database, potentially leading to sensitive data exposure, unauthorized modification of records, or complete compromise of the WordPress application data.\nThe flaw does not require authentication, meaning any network-reachable attacker can execute arbitrary SQL queries against the database without possessing valid user credentials.\nGiven that this vulnerability affects the integrity and confidentiality of the application's data layer, it presents a critical risk to site security and organizational data privacy.\nRemediation requires immediate update or replacement of the affected software component to prevent unauthorized data exfiltration or potential remote code execution via database-level interactions.",
  "technicalDetails": "The vulnerability resides in the way the Books Gallery plugin handles user-supplied input parameters within its database query construction logic. Specifically, the application fails to utilize parameterized queries or adequate input sanitization when processing requests before passing them to the database management system.\nThe root cause is the inclusion of unsanitized input into SQL statements. When an attacker sends a crafted request, the injected SQL payload is executed directly by the database engine. Because this endpoint is reachable without an active session, an unauthenticated attacker can manipulate the query structure to bypass security checks.\nThe exploitation flow initiates when an attacker transmits a maliciously crafted HTTP request targeting the vulnerable parameter. This payload typically includes SQL syntax designed to terminate the intended query and append a secondary, malicious query via a UNION-based or time-based injection technique.\nBy manipulating the SQL syntax, the attacker can force the database to return records from internal tables, including sensitive metadata, user credentials, or system configuration strings. If database permissions allow, an attacker could also perform data modification, such as updating administrative account email addresses or passwords, to escalate privileges.\nThe lack of authentication requirements significantly lowers the barrier to entry for potential attackers, as the vulnerability is exposed directly to the network. No prior interaction with the WordPress administration interface is necessary to trigger the flaw.\nPost-exploitation impact is severe. An attacker can leverage the SQL Injection to extract the entire contents of the database, leading to mass data breaches of user information. Furthermore, if the database user associated with the web application possesses excessive privileges (e.g., FILE access or administrative rights), an attacker might transition from SQL Injection to complete server compromise by writing web shells or executing OS-level commands through database functions.\nThe vulnerability persists across all versions of the plugin up to and including version 4.8.3, indicating a long-standing weakness in the component's data access layer that lacks the necessary abstraction to prevent injection attacks."
}
CVE-2026-96822: Unauthenticated SQL Injection in Books Gallery (CRITICAL Severity, CVSS: 9.3) | Sceawere