CVE-2026-104390: WordPress Booktics plugin <= 1.0.27 - Broken Access Control vulnerability
Published Oct 7, 2026
·Updated
Missing Authorization vulnerability in Arraytics Booktics booktics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booktics: from n/a through 1.0.27.
Affected Software
1 affected component
Arraytics Booktics<=1.0.27
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Booktics pluginto a version that resolves this vulnerability.Fixed in 1.0.28
Event History
Oct 7, 2026
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-privileged access (PR:L). It is remotely exploitable over the network and does not require user interaction.
2
What is the potential impact if exploited?
The reported impact is limited to confidentiality, with low confidentiality impact. No integrity or availability impact is indicated.
3
Which Booktics versions are affected?
Booktics versions through 1.0.27 are affected. The earliest affected version is not specified.