The Total Book Project WordPress Plugin Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Total Book Project plugin for WordPress, affecting all versions through 1.0. The issue arises from several functions lacking proper validation on user-controlled keys, enabling authenticated attackers with Contributor-level access or higher to manipulate book chapters that do not belong to them. This includes actions such as moving, deleting, or creating chapters.

Impact

Exploitation of this vulnerability allows for unauthorized manipulation of book chapters, including moving, deleting, or creating chapters in books that do not belong to the user.

Added: Nov 11, 2025, 4:42 AM
Updated: Nov 11, 2025, 4:42 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.8
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.