The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4.
id: CVE-2025-6058
info:
name: WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
author:
...