← WordPress Vulnerabilities
WordPress security by component

Booknetic

Booknetic is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 17, 2026; the highest published CVSS base score is 8.8.

Plugin slug: booknetic

CVE-2026-25439: Booknetic: Privilege escalation or authentication bypass

Booknetic is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 4.8.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedJun 17, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for booknetic
Safe version
Jun 17, 2026 CVE-2026-25439
Booknetic: Privilege escalation or authentication bypass
Booknetic is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 4.8.5. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.1
NVDPending
Mar 26, 2025 CVE-2024-13146
Booknetic: Cross-site request forgery
Booknetic is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending
Feb 25, 2025 CVE-2025-26926
Booknetic: Cross-site request forgery
Booknetic is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending