CVE-2025-26926: WordPress Booknetic plugin <= 4.0.9 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in fs-code Booknetic booknetic.This issue affects Booknetic: from n/a through <= 4.0.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26926?
CVE-2025-26926 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that could potentially allow an attacker to perform unauthorized actions on behalf of a user.
How do I fix CVE-2025-26926?
To mitigate CVE-2025-26926, users should update Booknetic to a version later than 4.0.9 where the vulnerability has been addressed.
What versions are affected by CVE-2025-26926?
CVE-2025-26926 affects all versions of Booknetic up to and including version 4.0.9.
What are the potential impacts of CVE-2025-26926?
The potential impacts of CVE-2025-26926 include unauthorized actions being taken on behalf of authenticated users, which may compromise user data.
Who is impacted by CVE-2025-26926?
Users and administrators of Booknetic versions 4.0.9 and earlier are directly impacted by CVE-2025-26926.