7.1
CVSSv3

CVE-2025-26910

CVSSv4: NA | CVSSv3: 7.1 | CVSSv2: NA | VMScore: 810 | EPSS: 0.0002 | KEV: Not Included
Published: 10/03/2025 Updated: 10/03/2025

Vulnerability Summary

Cross-Site Request Forgery and Stored XSS in WPBookit WordPress Plugin 1.0.1

Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit allows Stored XSS. This issue affects WPBookit: from n/a up to and including 1.0.1.

Solution

Update the WordPress WPBookit wordpress plugin to the latest available version (at least 1.0.2).
Vulnerable Product Search on Vulmon Subscribe to Product

iqonic design wpbookit