PT-2025-43052 · WordPress · Bg Book Publisher
Published
2025-10-22
·
Updated
2025-10-22
·
CVE-2025-11867
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bg Book Publisher versions prior to 1.26
Description
The Bg Book Publisher plugin for WordPress is susceptible to Stored Cross-Site Scripting through the
book author post meta, which is rendered using the [book author] shortcode. The plugin does not properly sanitize the meta value before displaying it, allowing authenticated attackers with contributor-level access or higher to inject malicious web scripts into pages. These scripts will execute when a user views the affected page.Recommendations
Update Bg Book Publisher to version 1.26 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bg Book Publisher