
🚨 CVE-2025-3810: WPBookit <= 1.0.2 - Insecure Dire... Zero auth required to hijack any WordPress admin account through WPBookit's broken edit_profile_data() - IDOR meets priv... https://zerodaysignal.com/vulnerability/CVE-2025-3810 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces CVE‑2025‑3810, an IDOR in WPBookit ≤ 1.0.2 that allows unauthorized hijacking of WordPress admin accounts, and provides a link for more information.
