PT-2025-12858 · WordPress · Booknetic

Veshraj Ghimire

·

Published

2025-03-26

·

Updated

2025-04-30

·

CVE-2024-13146

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Booknetic WordPress plugin versions prior to 4.1.5
Description The issue concerns a lack of CSRF check when creating Staff accounts, which could allow attackers to make logged-in admins add arbitrary Staff members via a CSRF attack. This could potentially be exploited by attackers to add unauthorized staff members.
Recommendations For versions prior to 4.1.5, update to version 4.1.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Staff account creation feature to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-13146

Affected Products

Booknetic