CVE-2025-3811: WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Email Update
The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the editnewdatacustomercallback() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3811?
CVE-2025-3811 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-3811?
To fix CVE-2025-3811, update the WPBookit plugin to version 1.0.3 or later.
What is the impact of CVE-2025-3811?
The impact of CVE-2025-3811 allows unauthorized users to escalate privileges and gain control over user account details.
Who is affected by CVE-2025-3811?
All users of the WPBookit plugin for WordPress up to version 1.0.2 are affected by CVE-2025-3811.
Is CVE-2025-3811 a known issue?
Yes, CVE-2025-3811 is a recognized vulnerability that has been officially documented and disclosed.