plugin

Wpbookit Pro Vulnerabilities

3 known security issues reported for the Wpbookit Pro WordPress plugin. Most recent disclosed Mar 23, 2026.

1 high 2 medium

Running Wpbookit Pro on your site? Check whether your installed version is affected.

Scan your site free

WPBookit Pro <= 1.6.18 - Authenticated (Subscriber+) Arbitrary File Upload

high

The WPBookit Pro - Appointment Booking Plugin for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.6.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files...

CVSS:
8.8
Affected:
up to 1.6.18
Fix:
No patched version reported
Disclosed:
Mar 23, 2026

CVE-2026-25413 on NVD →

WPBookit Pro <= 1.6.18 - Authenticated (Subscriber+) Privilege Escalation

medium

The WPBookit Pro - Appointment Booking Plugin for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges.

CVSS:
4.3
Affected:
up to 1.6.18
Fix:
No patched version reported
Disclosed:
Mar 23, 2026

CVE-2026-25414 on NVD →

WPBookit Pro <= 1.6.18 - Missing Authorization

medium

The WPBookit Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.6.18. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.6.18
Fix:
No patched version reported
Disclosed:
Jan 28, 2026

CVE-2026-25415 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database