First published: Fri Feb 07 2025(Updated: )
Missing Authorization vulnerability in blackandwhitedigital BookPress – For Book Authors allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BookPress – For Book Authors: from n/a through 1.2.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
blackandwhitedigital BookPress | <=1.2.7 | |
blackandwhitedigital BookPress | <=1.2.7 | |
Blackandwhitedigital Bookpress | <=1.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25167 has a medium severity level due to its potential for unauthorized access.
To fix CVE-2025-25167, update the BookPress – For Book Authors plugin to version 1.2.8 or later.
CVE-2025-25167 affects BookPress – For Book Authors versions up to and including 1.2.7.
CVE-2025-25167 is a Missing Authorization vulnerability that allows for improperly configured access control.
The vendor for the impacted product is blackandwhitedigital, specifically for the BookPress – For Book Authors software.