Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14068 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the edit_profile_data() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses and passwords, including administrators, and leverage that to gain access to their account. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 27 Jun 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iqonic
Iqonic wpbookit |
|
| CPEs | cpe:2.3:a:iqonic:wpbookit:*:*:*:*:free:wordpress:*:* | |
| Vendors & Products |
Iqonicdesign
Iqonicdesign wpbookit |
Iqonic
Iqonic wpbookit |
Wed, 21 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iqonicdesign
Iqonicdesign wpbookit |
|
| CPEs | cpe:2.3:a:iqonicdesign:wpbookit:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Iqonicdesign
Iqonicdesign wpbookit |
Fri, 09 May 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the edit_profile_data() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses and passwords, including administrators, and leverage that to gain access to their account. | |
| Title | WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:53:25.522Z
Reserved: 2025-04-18T18:08:49.740Z
Link: CVE-2025-3810
Updated: 2025-05-09T03:42:47.308Z
Status : Analyzed
Published: 2025-05-09T03:15:24.150
Modified: 2025-06-27T17:39:17.577
Link: CVE-2025-3810
No data.
OpenCVE Enrichment
Updated: 2026-04-22T01:45:05Z
EUVD