CVE-2026-62135: WordPress Booktics plugin <= 1.0.24 - Broken Access Control vulnerability
Published Sep 11, 2026
·Updated
Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.
Affected Software
1 affected component
wordpress/booktics<=1.0.24
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/bookticsto a version that resolves this vulnerability.Fixed in 1.0.25
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation. It is reachable over the network and requires no user interaction.
2
What security impact is reported?
The reported impact is integrity-only: an attacker may be able to make unauthorized changes. No confidentiality or availability impact is indicated by the provided severity vector.
3
Which installations should be considered affected?
WordPress sites using the Booktics plugin version 1.0.24 or earlier should be considered affected based on the reported version range.