CVE-2025-12135: WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting
The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csscode' parameter in all versions up to, and including, 1.0.6 due to a missing capability check on the savecustomecode() function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12135?
CVE-2025-12135 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-12135?
To mitigate CVE-2025-12135, update the WPBookit plugin to version 1.0.7 or later to ensure the vulnerability is patched.
Who is affected by CVE-2025-12135?
CVE-2025-12135 affects all users of the WPBookit plugin for WordPress versions up to and including 1.0.6.
What type of vulnerability is CVE-2025-12135?
CVE-2025-12135 is a Stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2025-12135 be exploited by unauthenticated users?
Yes, CVE-2025-12135 can be exploited by unauthenticated attackers due to the lack of capability checks.