9.8
CVSSv3

CVE-2025-3811

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00072 | KEV: Not Included
Published: 09/05/2025 Updated: 12/05/2025

Vulnerability Summary

WordPress WPBookit Plugin Unauthenticated Account Takeover via Privilege Escalation

The WPBookit WordPress plugin (versions up to 1.0.2) contains a serious privilege escalation vulnerability through its account takeover mechanism. The plugin's edit_newdata_customer_callback() function lacks proper user identity verification, which allows unauthenticated attackers to manipulate user email addresses. By changing email addresses arbitrarily, including those of administrators, malicious actors can subsequently reset user passwords and illegally access their accounts.

Vulnerable Product Search on Vulmon Subscribe to Product

iqonicdesign wpbookit