Wpbookit Iqonicdesign Wpbookit

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Iqonicdesign Wpbookit.

By the Year

In 2026 there have been 5 vulnerabilities in Iqonicdesign Wpbookit with an average score of 7.3 out of ten. Last year, in 2025 Wpbookit had 9 security vulnerabilities published. Right now, Wpbookit is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 1.61

Year Vulnerabilities Average Score
2026 5 7.30
2025 9 8.91
2024 1 9.30

It may take a day or so for new Wpbookit vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Iqonicdesign Wpbookit Security Vulnerabilities

WPBookit Pro <=1.6.18 Unrestricted Dangerous File Upload (WP)
CVE-2026-25413 9.9 - Critical - March 25, 2026

Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

Unrestricted File Upload

WPBookit Pro <=1.6.18: Privilege Escalation via Incorrect Privilege Assignment
CVE-2026-25414 8.8 - High - March 25, 2026

Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

Incorrect Privilege Assignment

WPBookit <1.0.8: Unauthorized Data Disclosure via get_customer_list
CVE-2026-1980 5.3 - Medium - March 04, 2026

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails, phone numbers, dates of birth, and gender.

Information Disclosure

WPBookit <=1.0.8 Stored XSS via wpb_user_name/email
CVE-2026-1945 7.2 - High - March 04, 2026

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

CVE-2026-25415: Missing Auth in WPBookit Pro <=1.6.18
CVE-2026-25415 5.3 - Medium - February 19, 2026

Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18.

AuthZ

Stored XSS in WPBookit 1.0.6 via css_code (Unauth)
CVE-2025-12135 7.2 - High - November 21, 2025

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to a missing capability check on the save_custome_code() function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

WPBookit 1.x Arbitrary File Upload RCE via image_upload_handle()
CVE-2025-7852 9.8 - Critical - July 24, 2025

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and including, 1.0.6. The plugins imageupload handler calls move_uploaded_file() on clientsupplied files without restricting allowed extensions or MIME types, nor sanitizing the filename. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Unrestricted File Upload

WPBookit 1.0.4 Arbitrary File Upload via image_upload_handle()
CVE-2025-6058 9.8 - Critical - July 12, 2025

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Unrestricted File Upload

WPBookit WP Plugin 1.0.2 Privilege Escalation via Unvalidated Account Takeover
CVE-2025-3811 9.8 - Critical - May 09, 2025

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the edit_newdata_customer_callback() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

Insecure Direct Object Reference / IDOR

WPBookit Plugin Priv Esc via Unauth Profile Update <=1.0.2
CVE-2025-3810 9.8 - Critical - May 09, 2025

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the edit_profile_data() function. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses and passwords, including administrators, and leverage that to gain access to their account.

Insecure Direct Object Reference / IDOR

Missing Auth in Iqonic WPBookit v1.0.1—ACL Constraint Flaw
CVE-2025-32254 5.3 - Medium - April 04, 2025

Missing Authorization vulnerability in Iqonic Design WPBookit allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WPBookit: from n/a through 1.0.1.

AuthZ

CSRF Stored XSS in WPBookit <1.0.2 (Iqonic Design)
CVE-2025-26910 - March 10, 2025

Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <= 1.0.1.

Session Riding

WPBookit <=1.6.9 arbitrary file upload via WPB_Profile_controller
CVE-2025-0357 9.8 - Critical - January 25, 2025

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Unrestricted File Upload

WPBookit <=1.6.4: Arbitrary User Password Chg Vulnerability
CVE-2024-10215 9.8 - Critical - January 09, 2025

The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

Insecure Direct Object Reference / IDOR

WPBookit <=1.6.0 SQL Injection Vulnerability
CVE-2024-54280 9.3 - Critical - December 16, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Injection.This issue affects WPBookit: from n/a through <= 1.6.0.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Iqonicdesign Wpbookit or by Iqonicdesign? Click the Watch button to subscribe.

subscribe