CVE-2026-1980
- EPSS 0.38%
- Veröffentlicht 04.03.2026 01:21:58
- Zuletzt bearbeitet 22.04.2026 21:26:58
The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to...
CVE-2026-1945
- EPSS 0.32%
- Veröffentlicht 04.03.2026 01:21:57
- Zuletzt bearbeitet 22.04.2026 21:26:58
The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes ...
CVE-2025-12135
- EPSS 0.25%
- Veröffentlicht 21.11.2025 07:31:51
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to a missing capability check on the save_custome_code() function. This makes it possible for ...
CVE-2025-7852
- EPSS 1.21%
- Veröffentlicht 24.07.2025 04:24:12
- Zuletzt bearbeitet 15.04.2026 00:35:42
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and including, 1.0.6. The plugin’s imag...
CVE-2025-6057
- EPSS 0.64%
- Veröffentlicht 12.07.2025 04:22:22
- Zuletzt bearbeitet 16.07.2025 14:57:56
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with ...
CVE-2025-6058
- EPSS 5.65%
- Veröffentlicht 12.07.2025 04:22:21
- Zuletzt bearbeitet 16.07.2025 14:57:37
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it pos...