CVE-2025-32254: WordPress WPBookit plugin <= 1.0.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPBookit: from n/a through <= 1.0.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32254?
The severity of CVE-2025-32254 is classified as a Missing Authorization vulnerability, which can allow unauthorized access to certain functionalities in WPBookit.
How do I fix CVE-2025-32254?
To fix CVE-2025-32254, update the WPBookit plugin to a version that is not affected, as the issue exists in versions up to 1.0.1.
What does CVE-2025-32254 affect?
CVE-2025-32254 affects the WPBookit plugin by Iqonic Design, specifically versions up to and including 1.0.1.
What are the potential impacts of CVE-2025-32254?
The potential impacts of CVE-2025-32254 include unauthorized access to restricted functionalities, which may compromise sensitive data or site integrity.
Is there a patch available for CVE-2025-32254?
Yes, the patch for CVE-2025-32254 can be applied by updating the WPBookit plugin to a version that addresses the vulnerability.