Privilege Escalation in WPBookit Plugin for WordPress
CVE-2025-3811
What is CVE-2025-3811?
The WPBookit plugin for WordPress is exposed to a privilege escalation risk that allows unauthenticated attackers to take over user accounts, including administrative ones. This vulnerability arises from inadequate validation of user identity during the process of updating user information, enabling attackers to modify email addresses of arbitrary users. Through the faulty edit_newdata_customer_callback() function, an attacker can exploit this weakness to reset a user's password and gain full access to their account. Admins and users are advised to check their plugin versions and apply necessary updates to enhance security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPBookit * <= 1.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved