Stored Cross-Site Scripting Vulnerability in WPBookit Plugin for WordPress
CVE-2025-12135

7.2HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
21 November 2025

What is CVE-2025-12135?

The WPBookit plugin for WordPress contains a vulnerability that enables stored cross-site scripting through the 'css_code' parameter. An attacker can exploit this due to the absence of a capability check in the save_custome_code() function, allowing unauthorized users to inject arbitrary scripts. This injected code can execute in the context of users who access the compromised pages, posing significant security risks.

Affected Version(s)

WPBookit * <= 1.0.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ryan Kozak
.
CVE-2025-12135 : Stored Cross-Site Scripting Vulnerability in WPBookit Plugin for WordPress