Junglewise Threat Intelligence

CVE-2026-39604: zookatron MyBookTable Bookstore Stored XSS

CVE-2026-39604 · Severity: medium · CVSS 5.9 · Published 2026-04-08

Executive brief

MyBookTable Bookstore is a WordPress plugin used to create and manage online book catalogs. A security flaw allows an attacker with high-level permissions to inject malicious scripts into the website. If a site visitor or administrator views the affected page, these scripts could redirect users to malicious sites, steal session information, or display unauthorized advertisements.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the zookatron MyBookTable Bookstore plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability allows an attacker with high privileges (such as an Author or higher) to inject arbitrary web scripts into the database. These scripts are subsequently executed in the browser of any user who visits the affected page. Exploitation requires the attacker to have network access to the WordPress administrative interface and involves minimal user interaction from the victim. While NVD lists the affected versions as <= 3.6.0, the primary source (Patchstack) indicates versions up to and including 3.6.3 are vulnerable, with no official patch currently available.

Affected products

  • zookatron MyBookTable Bookstore <= 3.6.0 (NVD); <= 3.6.3 (Patchstack)

Timeline

  • 2026-01-02: disclosed: Reported by researcher Jitlada to Patchstack
  • 2026-02-01: advisory: Initial advisory published by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References