Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WPBookit — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in WPBookit, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWE) associated with the vendor WPBookit and its software products. It collects vulnerability data primarily covering the period from 2020 to 2024, reflecting reported security issues across various releases and updates. The collection includes diverse weakness types such as cross-site scripting, injection flaws, and insecure direct object references, providing a comprehensive view of the security landscape for this specific product line. Here, security researchers and administrators can track a vendor's advisory history to understand how promptly and effectively vulnerabilities are addressed over time. Users can also gain a deeper understanding of specific weakness classes by observing how they manifest in real-world scenarios within the WPBookit ecosystem. Additionally, the page serves as a lookup tool for reviewing a product’s vulnerability history, allowing stakeholders to assess risk trends and identify recurring patterns in security defects. This resource is designed to support informed decision-making for patch management and security auditing without promoting any specific vendor or product features. By presenting this data in a structured manner, the page aims to enhance transparency and facilitate better security practices for users relying on WPBookit solutions. The information presented is derived from public disclosures and security research, ensuring that the data is accurate and relevant for professional use.

Vendor: Iqonic Design

CVE ID Title CVSS Severity Published
CVE-2026-1980 WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure CWE-200 5.3 Medium 2026-03-04
CVE-2026-1945 WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters CWE-79 7.2 High 2026-03-04
CVE-2025-12685 WPBookit <= 1.0.7 - Customer Deletion via CSRF 4.3 - 2026-01-02
CVE-2025-12135 WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High 2025-11-21
CVE-2025-7852 WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function CWE-434 9.8 Critical 2025-07-24
CVE-2025-6057 WPBookit <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 8.8 High 2025-07-12
CVE-2025-6058 WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical 2025-07-12
CVE-2025-3811 WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Email Update CWE-639 9.8 Critical 2025-05-09
CVE-2025-3810 WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover CWE-639 9.8 Critical 2025-05-09
CVE-2025-32254 WordPress WPBookit plugin <= 1.0.7 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-04-04
CVE-2025-26910 WordPress WPBookit plugin <= 1.0.1 - Cross Site Request Forgery (CSRF) Vulnerability CWE-352 7.1 High 2025-03-10
CVE-2025-0357 WPBookit <= 1.6.9 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical 2025-01-25
CVE-2024-10215 WPBookit <= 1.6.4 - Unauthenticated Arbitrary User Password Change CWE-639 9.8 Critical 2025-01-09
CVE-2024-54280 WordPress WPBookit plugin <= 1.6.0 - SQL Injection vulnerability CWE-89 9.3 Critical 2024-12-16

All 14 known CVE vulnerabilities affecting WPBookit with full Chinese analysis, references, and POCs where available.