Iqonic
Iqonic Wpbookit: vulnerabilidades y CVE
Iqonic Wpbookit tiene 14 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses4
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-1980 | Media (5.3) | 0.83% | — | 4 mar 2026 | The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible… |
| CVE-2026-1945 | Alta (7.2) | 0.32% | — | 4 mar 2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient input sanitization… |
| CVE-2025-12685 | Media (6.5) | 0.15% | — | 2 ene 2026 | The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack. |
| CVE-2025-12135 | Alta (7.2) | 0.29% | — | 21 nov 2025 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to a missing capability check on the save_custome_code()… |
| CVE-2025-7852 | Crítica (9.8) | 1.5% | — | 24 jul 2025 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and… |
| CVE-2025-6058 | Crítica (9.8) | 5.5% | — | 12 jul 2025 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and… |
| CVE-2025-6057 | Alta (8.8) | 0.66% | — | 12 jul 2025 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up to, and including, 1.0.4. This makes it possible for… |
| CVE-2025-3811 | Crítica (9.8) | 0.72% | — | 9 may 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to… |
| CVE-2025-3810 | Crítica (9.8) | 0.72% | — | 9 may 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to… |
| CVE-2025-32254 | Media (5.3) | 0.44% | — | 4 abr 2025 | Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPBookit: from n/a through <= 1.0.7. |
| CVE-2025-26910 | Media (6.1) | 0.14% | — | 10 mar 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <= 1.0.1. |
| CVE-2025-0357 | Crítica (9.8) | 1.1% | — | 25 ene 2025 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in versions up to, and including, 1.6.9.… |
| CVE-2024-10215 | Crítica (9.8) | 0.66% | — | 9 ene 2025 | The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass… |
| CVE-2024-54280 | Crítica (9.8) | 0.63% | — | 16 dic 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Injection.This issue affects WPBookit: from n/a through <= 1.6.0. |