PatchSiren

About Envato CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM About Envato CVE published 2026-06-26

CVE-2025-66123

CVE-2025-66123 is a MEDIUM-severity vulnerability in BookPro plugin versions <= 1.1.0, allowing unauthenticated Insecure Direct Object References (IDOR). The vulnerability was reported by [email protected] and is tracked by CWE-639. Defenders responsible for BookPro plugin deployments should assess exposure and apply patches or mitigations to prevent potential data breaches. As the source corpus is spa [truncated]