VendorsIqonicwpbookitany version
Vulnerabilities

Iqonic Design WPBookit any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2025-6058
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
Published 2025-07-12 · Analyzed
9.8EPSS 0.055
CVE-2025-0357
WPBookit <= 1.6.9 - Unauthenticated Arbitrary File Upload
Published 2025-01-25 · Analyzed
9.8EPSS 0.011
CVE-2025-3810
WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover
Published 2025-05-09 · Analyzed
9.8EPSS 0.007
CVE-2025-3811
WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Email Update
Published 2025-05-09 · Analyzed
9.8EPSS 0.007
CVE-2024-10215
WPBookit <= 1.6.4 - Unauthenticated Arbitrary User Password Change
Published 2025-01-09 · Analyzed
9.8EPSS 0.007
CVE-2024-54280
WordPress WPBookit plugin <= 1.6.0 - SQL Injection vulnerability
Published 2024-12-16 · Modified
9.8EPSS 0.006
CVE-2025-6057
WPBookit <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Upload
Published 2025-07-12 · Analyzed
8.8EPSS 0.007
CVE-2025-26910
WordPress WPBookit plugin <= 1.0.1 - Cross Site Request Forgery (CSRF) Vulnerability
Published 2025-03-10 · Modified
7.1EPSS 0.001
CVE-2025-32254
WordPress WPBookit plugin <= 1.0.7 - Broken Access Control vulnerability
Published 2025-04-04 · Modified
5.3EPSS 0.004