Description
Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7.
Published: 2025-02-07
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from a missing authorization check in the Black and White BookPress – For Book Authors WordPress plugin. The flaw permits users who should not have certain privileges to access or modify data, or to invoke administrative functions. The description explicitly notes incorrectly configured access control security levels, and the weakness is classified as CWE‑862. Because the description and CVE entry do not explicitly state the confidentiality, integrity and availability consequences, these impacts are inferred from the nature of an authorization bypass—an attacker could read protected data, alter content, or disrupt normal site operation.

Affected Systems

All installations of the Black and White BookPress – For Book Authors WordPress plugin with a version number of 1.2.7 or earlier are affected. The vulnerability applies from the initial release up to and including version 1.2.7.

Risk and Exploitability

The CVSS score of 8.2 places the issue in the high‑severity range. The EPSS score of less than 1% indicates a low probability of exploitation based on current activity patterns. The vulnerability is not listed in CISA’s KEV catalog, so it has not yet been confirmed as a known exploited weakness. The likely attack vector is through the plugin’s web interface; an authenticated user with low privileges could send crafted requests that bypass the intended security checks and gain unauthorized access to data or administrative functions. As the flaw allows unauthorized actions, it could compromise confidentiality, integrity and availability if an attacker escalates access to the WordPress instance.

Generated by OpenCVE AI on May 2, 2026 at 04:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest official plugin update (v1.2.8 or newer) to eliminate the missing authorization flaw
  • If an update cannot be applied immediately, disable the plugin or remove it from non‑administrator accounts and restrict its features to users with administrator privileges
  • After applying the patch, audit the plugin’s role and capability assignments to confirm that all endpoints enforce the correct permission checks

Generated by OpenCVE AI on May 2, 2026 at 04:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4070 Missing Authorization vulnerability in blackandwhitedigital BookPress – For Book Authors allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BookPress – For Book Authors: from n/a through 1.2.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in blackandwhitedigital BookPress – For Book Authors allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BookPress – For Book Authors: from n/a through 1.2.7. Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7.
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Blackandwhitedigital
Blackandwhitedigital bookpress
CPEs cpe:2.3:a:blackandwhitedigital:bookpress:*:*:*:*:*:wordpress:*:*
Vendors & Products Blackandwhitedigital
Blackandwhitedigital bookpress

Fri, 07 Feb 2025 10:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in blackandwhitedigital BookPress – For Book Authors allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BookPress – For Book Authors: from n/a through 1.2.7.
Title WordPress BookPress – For Book Authors Plugin <= 1.2.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Blackandwhitedigital Bookpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:37.609Z

Reserved: 2025-02-03T13:35:31.280Z

Link: CVE-2025-25167

cve-icon Vulnrichment

Updated: 2025-02-12T20:44:04.841Z

cve-icon NVD

Status : Modified

Published: 2025-02-07T10:15:22.430

Modified: 2026-04-23T15:25:44.280

Link: CVE-2025-25167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:45:34Z

Weaknesses