Stored Cross-Site Scripting Vulnerability in WPBookit Plugin for WordPress
CVE-2025-12135
7.2HIGH
What is CVE-2025-12135?
The WPBookit plugin for WordPress contains a vulnerability that enables stored cross-site scripting through the 'css_code' parameter. An attacker can exploit this due to the absence of a capability check in the save_custome_code() function, allowing unauthorized users to inject arbitrary scripts. This injected code can execute in the context of users who access the compromised pages, posing significant security risks.
Affected Version(s)
WPBookit * <= 1.0.6