WordPress Booktics Plugin Missing Authorization Vulnerability Allows Unauthenticated Addon Installation

Vulnerability

A vulnerability exists in the Booktics plugin for WordPress, specifically in versions through 1.0.16. The issue arises from a lack of proper capability checks in the 'Extension_Controller::update_item_permissions_check' function. This flaw enables unauthenticated attackers to install addon plugins, leading to unauthorized modification of data.

Impact

Exploitation of this vulnerability allows for the unauthorized installation of addon plugins, which could be used to modify data or potentially introduce malicious functionality to the WordPress site.

Remediation

Users are advised to update the Booktics plugin to version 1.0.17 or a newer patched version.

Added: Mar 10, 2026, 5:46 PM
Updated: Mar 10, 2026, 5:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
0.0
relevance
3.7
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.