Junglewise Threat Intelligence

CVE-2025-66123: About Envato BookPro IDOR in WordPress plugin

CVE-2025-66123 · Severity: medium · CVSS 5.3 · Published 2026-06-26

Executive brief

The BookPro plugin for WordPress, which is used for managing bookings and appointments, contains a security flaw that allows unauthorized access to data. An attacker can exploit this to view information they should not have access to by manipulating identifiers in web requests. This could lead to the exposure of sensitive customer or booking details without requiring any login credentials.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the BookPro plugin (ovabookpro) for WordPress in versions up to and including 1.1.0. The flaw stems from insufficient authorization checks when accessing specific objects or records via user-controlled input. A remote, unauthenticated attacker can exploit this by modifying parameters (such as IDs) in requests to access sensitive information or interact with data they are not authorized to view. As of the advisory date, no official patch has been released, and users are advised to monitor for updates or implement web application firewall (WAF) rules to mitigate the risk.

Affected products

  • About Envato / ovabookpro BookPro <= 1.1.0

Timeline

  • 2025-11-09: other: Vulnerability reported by researcher Phat RiO
  • 2026-06-26: advisory: Early warning sent to Patchstack customers
  • 2026-06-26: disclosed: Public disclosure of the vulnerability

References