External risk intelligence

Books Gallery SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96822

The vulnerability affects a WordPress plugin, which is a type of web application component typically deployed as part of a public-facing website. SQL injection in such plugins allows for potential interaction with the underlying database directly from the internet via the web interface.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns an unauthenticated SQL injection vulnerability found in a WordPress plugin, the Books Gallery. This type of vulnerability allows an attacker to manipulate database queries, potentially leading to unauthorized access to sensitive information or disruption of services. The main concern at this stage is to determine if this specific plugin and version are in use within your environment.

  • Attackers can inject malicious code into database queries.
  • This affects web applications using the Books Gallery plugin.
  • Confirm relevance to understand potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to a vulnerable Books Gallery installation. This would allow them to inject malicious SQL code into the application's database queries. If successful, this could lead to unauthorized access to sensitive data or other database compromises.

  • No authentication is required.
  • SQL injection through crafted requests.
  • Database compromise and data exposure.

Live Threat

Current exploitation, exposure, and threat context

This unauthenticated SQL injection vulnerability could allow an attacker to access sensitive information from the underlying database when supported by the advisory.

  • Database information could be exposed.
  • Via specially crafted network requests.
  • Leading to unauthorized data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical unauthenticated SQL injection vulnerability in the Books Gallery plugin impacts external-facing websites. Identifying the exact deployment of the affected plugin, confirming its internet reachability, and pinpointing the accountable application or website owner are the critical first steps. Once identified, a risk-based remediation plan, considering vendor coordination or temporary mitigation, should be developed and executed.

  • Application owners must own the issue.
  • Verify external exposure and criticality first.
  • Plan remediation based on risk and ownership.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Books Gallery plugin?

Books Gallery is a WordPress plugin designed to help site administrators showcase collections of books or media on their websites. It functions as an extension to the core WordPress platform, managing the storage and display of book-related data within the site's backend database.

What does CVE-2026-96822 mean by SQL injection?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. It means the plugin fails to properly filter input, allowing an attacker to inject their own database commands. By doing so, they can trick the application into revealing sensitive information it was never intended to share.

How do attackers trigger this SQL injection?

An attacker triggers this by sending specially crafted network requests to a vulnerable website. Because the plugin does not require authentication, the attacker does not need to log in to the site to execute these commands. Legitimate site usage or standard browsing by users will not accidentally trigger this flaw.

Do I need to worry if my site is not public?

Halo Surface Signal identifies this as a likely concern because WordPress plugins are frequently deployed on internet-facing web servers. If your instance is entirely internal and unreachable from the public internet, the practical risk is lower, but you should still assess whether any users or compromised systems within your network could reach the application.

When should I take action for this vulnerability?

You should act as soon as you confirm that your environment runs Books Gallery version 4.8.3 or earlier. The immediate priority is to locate where this plugin is deployed, confirm its network accessibility, and coordinate with the application owner to apply security updates or implement compensating controls to protect your data.

References