The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via several functions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform several actions like moving/deleting/creating chapters in books that do not belong to them.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ryanmoyer
Ryanmoyer the Total Book Project Wordpress Wordpress wordpress |
|
| Vendors & Products |
Ryanmoyer
Ryanmoyer the Total Book Project Wordpress Wordpress wordpress |
Tue, 11 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via several functions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform several actions like moving/deleting/creating chapters in books that do not belong to them. | |
| Title | The Total Book Project <= 1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Book Manipulation | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-11T03:30:50.707Z
Updated: 2025-11-11T03:30:50.707Z
Reserved: 2025-10-23T18:32:44.001Z
Link: CVE-2025-12126
No data.
Status : Received
Published: 2025-11-11T04:15:46.333
Modified: 2025-11-11T04:15:46.333
Link: CVE-2025-12126
No data.