Wpbookit
Vendor:
First CVE: Dec 16, 2024 · Active for 1 year
9
Total CVEs
More Total CVEs than 88% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 80% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wpbookit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 16, 2024
19 months ago
Most Recent CVE
Jul 12, 2025
380 days ago
CVE Severity & Scoring
Wpbookit9 CVEs
22%
11%
67%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6058CRITICAL The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type | Jul 12, 2025 | 9.8 | 43 | NO | YES |
CVE-2025-3810CRITICAL The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly val | May 9, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-3811CRITICAL The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly val | May 9, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-0357CRITICAL The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in | Jan 25, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-10215CRITICAL The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled acces | Jan 9, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-6057HIGH The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up to, and inclu | Jul 12, 2025 | 8.8 | 26 | NO | NO |
CVE-2024-54280CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Injection.This issue affects WPBook | Dec 16, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-26910MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <= 1.0.1. | Mar 10, 2025 | 6.1 | 20 | NO | NO |
CVE-2025-32254MEDIUM Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPBookit: from n/a through | Apr 4, 2025 | 5.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Wpbookit
Top CWEs
Versions
No cataloged versions.