PatchSiren cyber security CVE debrief
CVE-2026-27400 Ovatheme CVE debrief
CVE-2026-27400 is a high-severity vulnerability in the BookPro plugin, affecting versions up to 1.1.0. The vulnerability allows unauthenticated attackers to delete arbitrary files. With a CVSS score of 8.6, this issue poses a significant risk to affected systems. The vulnerability was published on June 17, 2026, and immediately gained attention due to its severity and potential impact. Users of the BookPro plugin should take immediate action to mitigate this vulnerability.
- Vendor
- Ovatheme
- Product
- BookPro
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and users of the BookPro plugin, especially those using versions up to 1.1.0, should be concerned about this vulnerability. The unauthenticated arbitrary file deletion vulnerability can lead to significant security risks, including data loss and potential system compromise.
Technical summary
The CVE-2026-27400 vulnerability in the BookPro plugin allows unauthenticated attackers to delete arbitrary files. This is a high-severity issue with a CVSS score of 8.6. The vulnerability is characterized by the following CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H. This indicates that the vulnerability can be exploited over the network (AV:N), requires low attack complexity (AC:L), and does not require any privileges (PR:N) or user interaction (UI:N). The vulnerability is classified under CWE-22, which refers to Improper Limitation of a Pathname to a Restricted Directory.
Defensive priority
High
Recommended defensive actions
- Update the BookPro plugin to a version beyond 1.1.0, if available.
- Restrict access to the BookPro plugin to only trusted users.
- Implement additional security measures, such as file access controls and monitoring.
- Regularly review and update plugins and software to prevent similar vulnerabilities.
- Consider using a Web Application Firewall (WAF) to detect and prevent attacks.
- Monitor system logs for suspicious activity related to file deletion.
- Perform regular backups to minimize data loss in case of an attack.
Evidence notes
The information provided is based on data from the National Vulnerability Database (NVD) and Patchstack. The CVE record and NVD detail pages provide official information about the vulnerability. The Patchstack reference offers mitigation details specific to the BookPro plugin.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-27400 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-27400
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-27400 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-27400
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.