← WordPress Vulnerabilities
WordPress security by component

Library Viewer

Library Viewer is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Feb 02, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: library-viewer

CVE-2025-15396: Library Viewer: Cross-site scripting

Library Viewer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedFeb 02, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 02, 2026 CVE-2025-15396
Library Viewer: Cross-site scripting
Library Viewer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Dec 29, 2023 CVE-2023-32101
Library Viewer: An open redirect
Library Viewer is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVD6.1
Sep 04, 2023 CVE-2023-32102
Library Viewer: Cross-site scripting
Library Viewer is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4