Vulnerability Description
The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.
CVSS Score
MEDIUM
References
FAQ
What is CVE-2025-12685?
CVE-2025-12685 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.
How severe is CVE-2025-12685?
CVE-2025-12685 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12685?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.