CVE-2025-48142

8.8

Saad Iqbal · Bookify

An incorrect privilege assignment vulnerability in the Bookify WordPress plugin allows authenticated users to escalate their privileges to administrative levels.

Executive summary

A critical privilege escalation vulnerability in the Bookify plugin for WordPress allows low-privileged users to gain administrative control over the affected installation.

Vulnerability

The vulnerability is categorized as an Incorrect Privilege Assignment (CWE-266), which permits an authenticated user to perform actions outside of their intended scope. Based on the CVSS vector (PR:L), the attacker must possess an active user account on the system to trigger this escalation.

Business impact

Successful exploitation of this flaw allows a standard user to achieve full administrative access to the WordPress site. This leads to complete system compromise, including the ability to modify site content, exfiltrate sensitive data, or install malicious backdoors, which poses a severe risk to organizational integrity and data security. The CVSS score of 8.8 reflects the high impact on confidentiality, integrity, and availability.

Remediation

Immediate Action: As no specific patched version is currently confirmed, administrators should deactivate and uninstall the Bookify plugin until a secure update is released by the vendor.

Proactive Monitoring: Security teams should audit WordPress user accounts for unauthorized administrative role changes or suspicious account creation activity.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized requests to administrative endpoints, though this should be considered a temporary measure pending plugin removal.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high severity and the potential for total administrative takeover, immediate removal of the Bookify plugin is the only effective way to eliminate this risk. Organizations should prioritize verifying the security of their WordPress user base and auditing logs for any signs of unauthorized privilege changes until the vendor provides a verified fix.

More Saad Iqbal CVEs

Sources

Originally found and disclosed by Denver Jackson | Patchstack Bug Bounty Program, per the CVE Program record.