
RS WP Book Showcase – A Complete Book Catalogue & Library System Security & Risk Analysis
wordpress.org/plugins/rs-wp-books-showcasePremier WordPress book gallery plugin, offering advanced search options and multiple layouts for effortless book showcasing.
Is RS WP Book Showcase – A Complete Book Catalogue & Library System Safe to Use in 2026?
Use With Caution
Score 57/100RS WP Book Showcase – A Complete Book Catalogue & Library System has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The 'rs-wp-books-showcase' plugin version 6.7.58 exhibits a mixed security posture. While it demonstrates strengths in areas like the absence of dangerous functions and a reasonable percentage of properly escaped output, significant concerns arise from its attack surface and historical vulnerability data. The plugin exposes a considerable number of entry points, with a notable portion lacking proper authentication or permission checks, particularly AJAX handlers and REST API routes. This uncontrolled access significantly increases the risk of unauthorized actions or data manipulation.
The taint analysis reveals flows with unsanitized paths, which, despite not reaching a critical or high severity in this scan, indicate potential weaknesses in input validation that could be exploited. The vulnerability history is particularly concerning, with two known medium-severity CVEs currently unpatched, both related to code injection and cross-site scripting. This pattern suggests recurring issues with how user input is handled, and the fact that these vulnerabilities are not patched implies a lack of diligent security maintenance or a delayed response to reported issues.
In conclusion, while the plugin has some positive security signals, the combination of a large, unprotected attack surface and a history of unpatched code injection and XSS vulnerabilities points to a moderate to high-security risk. Users should exercise caution and prioritize updating to a version that addresses these historical issues, if available. The current version's unprotected entry points and past vulnerabilities warrant careful consideration.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Unpatched CVEs (2 medium)
- Flows with unsanitized paths
- SQL queries without prepared statements
RS WP Book Showcase – A Complete Book Catalogue & Library System Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
RS WP Book Showcase <= 6.7.41 - Unauthenticated Arbitrary Shortcode Execution
RS WP Book Showcase <= 6.7.40 - Authenticated (Contributor+) Stored Cross-Site Scripting
RS WP Book Showcase – A Complete Book Catalogue & Library System Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
RS WP Book Showcase – A Complete Book Catalogue & Library System Attack Surface
AJAX Handlers 16
REST API Routes 2
Shortcodes 15
WordPress Hooks 84
Maintenance & Trust
RS WP Book Showcase – A Complete Book Catalogue & Library System Maintenance & Trust
Maintenance Signals
Community Trust
RS WP Book Showcase – A Complete Book Catalogue & Library System Alternatives
No alternatives data available yet.
RS WP Book Showcase – A Complete Book Catalogue & Library System Developer Profile
14 plugins · 6K total installs
How We Detect RS WP Book Showcase – A Complete Book Catalogue & Library System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rs-wp-books-showcase/includes/import-books-from-json/import-books-from-json.css/wp-content/plugins/rs-wp-books-showcase/includes/import-books-from-json/import-books-from-json.js/wp-content/plugins/rs-wp-books-showcase/admin/css/admin-notice.css/wp-content/plugins/rs-wp-books-showcase/includes/import-books-from-json/import-books-from-json.js/wp-content/plugins/rs-wp-books-showcase/admin/js/admin-notice.jsrs-wp-books-showcase/includes/import-books-from-json/import-books-from-json.css?ver=rs-wp-books-showcase/includes/import-books-from-json/import-books-from-json.js?ver=rs-wp-books-showcase/admin/css/admin-notice.css?ver=rs-wp-books-showcase/admin/js/admin-notice.js?ver=HTML / DOM Fingerprints
rswpbs-amz-admin-noticeamz-notice-sub-headingrswpbs-amz-admin-notice-btn-wrapperrswpbs-notice-dismiss-linksrswpbs-dismiss-foreverrswpbs-remind-laterimport-books-from-amazon-btn<!-- Rest of your notice HTML and JavaScript remains the same --><!-- Only proceed if there are books and a books page exists --><!-- Check if a books page exists (assuming it might be identified by a specific slug or template) --><!-- Check if the current user has the required capabilities (admin privileges) -->+7 moredata-noncerswpbs_amz_notice_dismissed_foreverrswpbs_amz_notice_dismissed_timerswpbs_import_books_from_json_page/wp-json/rswpbs/v1/books