WordPress security by component
BookPro
Plugin description
BookPro is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 8.6.
Plugin slug:
ovabookproLatest vulnerability
CVE-2025-66123: BookPro: A security weakness
BookPro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.1.0.
| Safe version |
|
||
|---|---|---|---|
| Jun 26, 2026 |
CVE-2025-66123
BookPro: A security weakness
BookPro is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.1.0.
|
> 1.1.0 |
CVE5.3
NVDPending
|
| Jun 17, 2026 |
CVE-2026-27400
BookPro: Arbitrary file deletion
BookPro is affected by arbitrary file deletion. The vulnerable path is reachable without authentication. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is n/a through 1.1.0.
|
> 1.1.0 |
CVE8.6
NVDPending
|