cleantalk
Vulnerabilities and Security Researches

Library Viewer, CVE-2025-15396

CVE, Research URL

CVE-2025-15396

Application

Library Viewer

Published on
Feb 02, 2026
Research Description
The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected versions
max 3.2.0.
Status
vulnerable