Vulnerabilities
Summary — last 7 days
New vulnerabilities3,043▲ 582 vs. last week
Critical / high1,452▲ 283 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)393▲ 186 vs. last week
29 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (2.7) | 0.32% | — | Bookit Booking Appointment CalendarAI | 9/18/2026 | 9/18/2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment… | |
| Deferred | Low (2.7) | 0.28% | — | Stylemixthemes BookitAI | 9/18/2026 | 9/18/2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments. | |
| Deferred | Medium (5.3) | 0.34% | — | Stylemixthemes BookitAI | 9/13/2026 | 9/14/2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information. | |
| Deferred | Medium (5.3) | 0.18% | — | Stylemixthemes BookitAI | 9/3/2026 | 9/4/2026 | Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | |
| Deferred | High (7.5) | 0.48% | — | Stellarwp BookitAILiquidweb BookitAI | 6/2/2026 | 7/22/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a before 2.5.4.1. | |
| Deferred | High (8.8) | 0.29% | — | Iqonicdesign Wpbookit PROAI | 3/25/2026 | 6/17/2026 | Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Deferred | Critical (9.9) | 0.33% | — | Iqonicdesign Wpbookit PROAI | 3/25/2026 | 6/17/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Deferred | Medium (5.3) | 0.83% | — | Iqonic WpbookitAI | 3/4/2026 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails,… | |
| Deferred | High (7.2) | 0.32% | — | Iqonic WpbookitAI | 3/4/2026 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Deferred | Medium (5.3) | 0.22% | — | Iqonicdesign Wpbookit PROAI | 2/19/2026 | 6/17/2026 | Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Deferred | Medium (6.5) | 0.15% | — | Iqonic WpbookitAI | 1/2/2026 | 6/17/2026 | The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack. | |
| Deferred | Medium (5.3) | 0.70% | — | Stylemixthemes BookitAI | 12/12/2025 | 6/17/2026 | The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options. | |
| Deferred | High (7.2) | 0.29% | — | Iqonic WpbookitAI | 11/21/2025 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to a missing capability check on the save_custome_code() function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Deferred | High (7.5) | 0.26% | — | Stylemixthemes BookitAI | 11/12/2025 | 6/17/2026 | The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated… | |
| Deferred | Critical (9.8) | 1.5% | — | Iqonic WpbookitAI | 7/24/2025 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and including, 1.0.6. The plugin’s image‐upload handler calls move_uploaded_file() on client‐supplied files… | |
| Analyzed | Critical (9.8) | 5.5% | — | Iqonic Wpbookit | 7/12/2025 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Analyzed | High (8.8) | 0.66% | — | Iqonic Wpbookit | 7/12/2025 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the… | |
| Analyzed | Critical (9.8) | 0.72% | — | Iqonic Wpbookit | 5/9/2025 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the edit_newdata_customer_callback() function. This makes it… | |
| Analyzed | Critical (9.8) | 0.72% | — | Iqonic Wpbookit | 5/9/2025 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the edit_profile_data() function. This makes it… | |
| Modified | Medium (5.3) | 0.44% | — | Iqonic Wpbookit | 4/4/2025 | 6/17/2026 | Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPBookit: from n/a through <= 1.0.7. | |
| Modified | Medium (6.1) | 0.14% | — | Iqonic Wpbookit | 3/10/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <= 1.0.1. | |
| Analyzed | Critical (9.8) | 1.1% | — | Iqonic Wpbookit | 1/25/2025 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Analyzed | Critical (9.8) | 0.66% | — | Iqonic Wpbookit | 1/9/2025 | 6/17/2026 | The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to… | |
| Modified | Critical (9.8) | 0.63% | — | Iqonic Wpbookit | 12/16/2024 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Injection.This issue affects WPBookit: from n/a through <= 1.6.0. | |
| Deferred | Medium (6.5) | 0.48% | — | Theeventscalendar BookitAI | 5/17/2024 | 6/17/2026 | Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0. |