Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WPBookit — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in WPBookit, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with the WPBookit plugin, developed by its respective vendor. It aggregates a comprehensive list of security flaws discovered in this WordPress booking solution, covering incidents reported and analyzed from 2018 through the present day. Visitors can utilize this resource to track the vendor’s historical security advisories, gain a deeper understanding of specific weakness classes such as stored cross-site scripting or insecure direct object references, and examine the complete vulnerability history of the product to assess its long-term security posture. The data is organized to facilitate efficient research for security professionals, auditors, and site administrators who need to evaluate the risk exposure of installations using WPBookit. By reviewing the collected entries, users can identify patterns in flaw types, understand the severity of past issues, and make informed decisions regarding plugin updates or alternative solutions. This centralized view eliminates the need to search multiple disparate sources for vulnerability information, providing a clear and structured overview of the security landscape surrounding this specific tool. The page strictly focuses on factual reporting of known weaknesses without including marketing commentary or promotional material. All listed items are cross-referenced with available documentation to ensure accuracy and context for each reported incident.

Vendor: Iqonic Design

CVE IDTitleCVSSSeverityPublished
CVE-2026-1980 WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure CWE-200 5.3 Medium2026-03-04
CVE-2026-1945 WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters CWE-79 7.2 High2026-03-04
CVE-2025-12685 WPBookit <= 1.0.7 - Customer Deletion via CSRF 4.3 -2026-01-02
CVE-2025-12135 WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2025-11-21
CVE-2025-7852 WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function CWE-434 9.8 Critical2025-07-24
CVE-2025-6057 WPBookit <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 8.8 High2025-07-12
CVE-2025-6058 WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical2025-07-12
CVE-2025-3811 WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Email Update CWE-639 9.8 Critical2025-05-09
CVE-2025-3810 WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover CWE-639 9.8 Critical2025-05-09
CVE-2025-32254 WordPress WPBookit plugin <= 1.0.7 - Broken Access Control vulnerability CWE-862 5.3 Medium2025-04-04
CVE-2025-26910 WordPress WPBookit plugin <= 1.0.1 - Cross Site Request Forgery (CSRF) Vulnerability CWE-352 7.1 High2025-03-10
CVE-2025-0357 WPBookit <= 1.6.9 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical2025-01-25
CVE-2024-10215 WPBookit <= 1.6.4 - Unauthenticated Arbitrary User Password Change CWE-639 9.8 Critical2025-01-09
CVE-2024-54280 WordPress WPBookit plugin <= 1.6.0 - SQL Injection vulnerability CWE-89 9.3 Critical2024-12-16

All 14 known CVE vulnerabilities affecting WPBookit with full Chinese analysis, references, and POCs where available.