Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.29% | — | Iqonicdesign Wpbookit PROAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Aplazada | Crítica (9.9) | 0.33% | — | Iqonicdesign Wpbookit PROAI | 25/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Aplazada | Media (5.3) | 0.83% | — | Iqonic WpbookitAI | 4/3/2026 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails,… | |
| Aplazada | Alta (7.2) | 0.33% | — | Iqonic WpbookitAI | 4/3/2026 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.22% | — | Iqonicdesign Wpbookit PROAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Aplazada | Media (6.5) | 0.15% | — | Iqonic WpbookitAI | 2/1/2026 | 17/6/2026 | The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack. | |
| Aplazada | Alta (7.2) | 0.29% | — | Iqonic WpbookitAI | 21/11/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to a missing capability check on the save_custome_code() function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Crítica (9.8) | 1.5% | — | Iqonic WpbookitAI | 24/7/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and including, 1.0.6. The plugin’s image‐upload handler calls move_uploaded_file() on client‐supplied files… | |
| Analizada | Crítica (9.8) | 6.0% | — | Iqonic Wpbookit | 12/7/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Analizada | Alta (8.8) | 0.71% | — | Iqonic Wpbookit | 12/7/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the… | |
| Analizada | Crítica (9.8) | 0.72% | — | Iqonic Wpbookit | 9/5/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the edit_newdata_customer_callback() function. This makes it… | |
| Analizada | Crítica (9.8) | 0.72% | — | Iqonic Wpbookit | 9/5/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the edit_profile_data() function. This makes it… | |
| Modificada | Media (5.3) | 0.44% | — | Iqonic Wpbookit | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPBookit: from n/a through <= 1.0.7. | |
| Modificada | Media (6.1) | 0.14% | — | Iqonic Wpbookit | 10/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <= 1.0.1. | |
| Analizada | Crítica (9.8) | 1.1% | — | Iqonic Wpbookit | 25/1/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Analizada | Crítica (9.8) | 0.66% | — | Iqonic Wpbookit | 9/1/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 0.63% | — | Iqonic Wpbookit | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Injection.This issue affects WPBookit: from n/a through <= 1.6.0. |