---
id: CVE-2025-12126
title: >-
  The The Total Book Project plugin for WordPress is vulnerable to Insecure
  Direct Object Reference in all versions up to, and including, 1.0 via several
  functions due to missing validation on a user controlled key
summary: >-
  The The Total Book Project plugin for WordPress is vulnerable to Insecure
  Direct Object Reference in all versions up to, and including, 1.0 via several
  functions due to missing validation on a user controlled key. This makes it
  possible …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-639
published: '2025-11-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12126'
references:
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3392629%40the-total-book-project&new=3392629%40the-total-book-project
    label: security@wordfence.com
  - url: 'https://wordpress.org/plugins/the-total-book-project/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/e1b473fd-2444-4a54-b558-4656634a6903?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00198
epssPercentile: 0.08785
ingestedAt: '2026-10-07T21:54:15.012Z'
---

## Overview

The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via several functions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform several actions like moving/deleting/creating chapters in books that do not belong to them.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
