9.8
CVSSv3

CVE-2025-0357

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00109 | KEV: Not Included
Published: 25/01/2025 Updated: 25/01/2025

Vulnerability Summary

Arbitrary File Upload Vulnerability in WPBookit Plugin Pre-1.7

The WPBookit plugin for WordPress has a vulnerability that allows arbitrary file uploads. This happens because it does not properly check file types in the 'WPB_Profile_controller::handle_image_upload' function. Versions up to and including 1.6.9 are affected. Unauthenticated attackers can upload any files to the server of an affected site. This may lead to remote code execution.

Vulnerable Product Search on Vulmon Subscribe to Product

iqonic design wpbookit