
🚨 CVE-2025-3811: WPBookit <= 1.0.2 - Insecure Dire... Zero-auth IDOR lets you hijack any WP admin by swapping their email in edit_newdata_customer_callback() - password reset... https://zerodaysignal.com/vulnerability/CVE-2025-3811 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
A new zero‑auth IDOR vulnerability (CVE‑2025‑3811) in WPBookit <=1.0.2 allows hijacking any WordPress admin by swapping their email in the edit_newdata_customer_callback() function.
