PT-2025-46273 · WordPress · The Total Book Project

Athiwat Tiprasaharn

·

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-12126

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Total Book Project plugin for WordPress versions prior to 1.1
Description The software is susceptible to an Insecure Direct Object Reference issue. This impacts authenticated attackers with Contributor-level access or higher, allowing them to perform unauthorized actions on books and chapters they do not own. The issue stems from a lack of validation on a user-controlled key within several functions.
Recommendations Update to version 1.1 or later.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-12126

Affected Products

The Total Book Project