← WordPress Vulnerabilities
WordPress security by component

BookPro

BookPro is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 8.6.

Plugin slug: ovabookpro

CVE-2025-66123: BookPro: A security weakness

BookPro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.1.0.

PublishedJun 26, 2026
Known safe version> 1.1.0
Safe version
Jun 26, 2026 CVE-2025-66123
BookPro: A security weakness
BookPro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.1.0.
> 1.1.0
CVE5.3
NVDPending
Jun 17, 2026 CVE-2026-27400
BookPro: Arbitrary file deletion
BookPro is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is n/a through 1.1.0.
> 1.1.0
CVE8.6
NVDPending