WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters
WPBookit
Minimum safe version
1.6.10
Update to 1.6.10 or later to address 12 fixable vulnerabilities
WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure
WPBookit <= 1.0.7 - Customer Deletion via CSRF
CVE-2025-12135
WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
WPBookit <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Upload
WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Email Update
WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover
CVE-2025-32254
CVE-2025-26910
WPBookit <= 1.6.9 - Unauthenticated Arbitrary File Upload
CVE-2024-10215