Junglewise Threat Intelligence

CVE-2026-62135: Booktics broken access control vulnerability

CVE-2026-62135 · Severity: medium · CVSS 5.3 · Published 2026-09-11

Technologies: Arraytics Booktics. Vendors: Arraytics.

Executive brief

Booktics is a WordPress plugin for event ticketing and booking. An unauthenticated attacker can bypass access controls to view or access pages and data they should not be permitted to access, potentially exposing sensitive customer or event information.

Technical details

The vulnerability is a broken access control flaw in Booktics WordPress plugin versions 1.0.24 and earlier. The plugin fails to properly enforce authorization checks, allowing unauthenticated users to access restricted pages and perform actions they should not be permitted to perform. The attack vector is network-based and requires no authentication or user interaction. An attacker can exploit this to view sensitive data belonging to other users or access functionality reserved for privileged roles. The issue is resolved in version 1.0.25 and later.

Affected products

  • Arraytics Booktics 1.0.24 and earlier

Timeline

  • 2026-08-27: disclosed: Reported to Patchstack
  • 2026-09-10: advisory: Published by Patchstack
  • 2026-09-10: patched: Version 1.0.25 released

References

Related threats