WP BookWidgets

WP BookWidgets has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for WP BookWidgets has a vendor fix available, so running the current release closes it.

All of these findings were reported by zaim. WP BookWidgets is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WP BookWidgets vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-10139

WP BookWidgets <= 0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
WP BookWidgets banner
Latestv0.10

WP BookWidgets

remko

Author

remko

0.0(0)
0/100
Last Updated
2025-10-17 (11mo ago)
Active Installs
40+
Downloads
3,750
Requires WP
4.0+
Requires PHP
0+
Tested up to
WP 6.8.8
Created
2016-11-07 (10y ago)

Integrate BookWidgets widgets in your WordPress site. Quickly embed or link to widgets by shortcode. Use one of the shortcodes in your page or posts to link or embed widgets. [bw_link]: Link to a widget Use the link of the widget from the “Share” dialog in BookWidgets: Have a look at [bw_link url="https://www.bookwidgets.com/play/ThIsIsa-LiNk123?teacher_id=123456"]my widget[/bw_link] If you enabled sharing by shortcode for the widget, you can also link using the shortcode of the widget: Have a look at [bw_link code="ABCDE"]my widget[/bw_link] [bw_embed]: Embed a widget Use the link of the widget from the “Share” dialog in BookWidgets: [bw_embed url="https://www.bookwidgets.com/play/ThIsIsa-LiNk123?teacher_id=123456"] If you enabled sharing by shortcode for the widget, you can also link using the shortcode of the widget: [bw_embed code="ABCDE"] Supported parameters: code: Widget shortcode width: Width of the widget frame height: Height of the widget frame allowfullscreen: set this to 1 to add a fullscreen button in the bottom right corner

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C