← WordPress Vulnerabilities
WordPress security by component

MyBookTable Bookstore

MyBookTable Bookstore is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Apr 08, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: mybooktable

CVE-2026-39604: MyBookTable Bookstore: Cross-site scripting

MyBookTable Bookstore is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.6.0.

PublishedApr 08, 2026
Known safe version> 3.6.0
Safe version
Apr 08, 2026 CVE-2026-39604
MyBookTable Bookstore: Cross-site scripting
MyBookTable Bookstore is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.6.0.
> 3.6.0
CVE5.9
NVDPending
Dec 31, 2025 CVE-2025-62743
MyBookTable Bookstore: Cross-site scripting
MyBookTable Bookstore is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jan 07, 2025 CVE-2025-22301
MyBookTable Bookstore: Cross-site request forgery
MyBookTable Bookstore is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Mar 27, 2024 CVE-2024-29772
MyBookTable Bookstore: Cross-site scripting
MyBookTable Bookstore is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Nov 30, 2023 CVE-2023-48331
MyBookTable Bookstore by Stormhill Media: Cross-site request forgery
MyBookTable Bookstore by Stormhill Media is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8