N/A
2026-02-05< 1.6.4
Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via CSV Import
Minimum safe version
2.18
Update to 2.18 or later to address 3 fixable vulnerabilities
Tune Library <= 1.6.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via CSV Import
WordPress Tune Library Plugin <= 2.17 - SQL Injection
CVE-2015-3314