9.8
CVSSv3

CVE-2024-10215

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00326 | KEV: Not Included
Published: 09/01/2025 Updated: 09/01/2025

Vulnerability Summary

Unauthorized Password Reset Vulnerability in WPBookit WordPress Plugin

The WPBookit plugin for WordPress has a vulnerability in versions up to 1.6.4. This is an Arbitrary User Password Change issue. The plugin lets users access objects and bypass authorization. Unauthenticated attackers can change user passwords. They can even take over administrator accounts.

Vulnerable Product Search on Vulmon Subscribe to Product

iqonic design wpbookit