plugin

The Total Book Project Vulnerabilities

1 known security issue reported for the The Total Book Project WordPress plugin. Most recent disclosed Nov 10, 2025.

1 medium

Running The Total Book Project on your site? Check whether your installed version is affected.

Scan your site free

The Total Book Project <= 1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Book Manipulation

medium

The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via several functions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform se...

CVSS:
5.4
Affected:
up to 1.0
Fixed in:
1.1
Disclosed:
Nov 10, 2025

CVE-2025-12126 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database