📦 Wpbookit

by Iqonic

🔍 What is Wpbookit?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-6058

CRITICAL CVSS 9.8 Jul 12, 2025

The WPBookit WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability can lead to remote code execution on affected websites....

CVE-2025-3810

CRITICAL CVSS 9.8 May 9, 2025

The WPBookit WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to change any user's email and password, including administrators. This enables complete ...

CVE-2025-0357

CRITICAL CVSS 9.8 Jan 25, 2025

The WPBookit WordPress plugin allows unauthenticated attackers to upload arbitrary files due to insufficient file type validation. This vulnerability affects versions up to 1.6.9 and can lead to remot...

CVE-2024-10215

CRITICAL CVSS 9.8 Jan 9, 2025

The WPBookit WordPress plugin vulnerability allows unauthenticated attackers to change any user's password, including administrators, by bypassing authorization checks. This affects all WordPress site...

CVE-2024-54280

CRITICAL CVSS 9.3 Dec 16, 2024

This SQL injection vulnerability in the WPBookit WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects all WordPress sites running WPBookit versions up to 1.6...

CVE-2025-26910

HIGH CVSS 7.1 Mar 10, 2025

A Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design's WPBookit WordPress plugin allows attackers to perform stored cross-site scripting (XSS) attacks. This affects WordPress sites using...

CVE-2025-32254

MEDIUM CVSS 5.3 Apr 4, 2025

This CVE describes a missing authorization vulnerability in the WPBookit WordPress plugin that allows attackers to access functionality not properly constrained by access control lists (ACLs). Attacke...