Tune Library
Tune Library has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include SQL Injection.
Every one of the 2 issues recorded for Tune Library has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Tune Library is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2015-3314Tune Library < 1.5.5 - SQL Injection
Read the full analysisVulnerability Records

Tune Library
Author
Yannick Lefebvre
This plugin is used to import an XML iTunes Music Library file into your WordPress database. Once imported, you can display a complete listing of your music collection on a page of your WordPress site. You can try it out in a temporary copy of WordPress here.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C