710
VMScore

CVE-2025-26910

CVSSv4: NA | CVSSv3: 6.1 | CVSSv2: NA | VMScore: 710 | EPSS: 0.0002 | KEV: Not Included
Published: 10/03/2025 Updated: 21/05/2025

Vulnerability Summary

Cross-Site Request Forgery and Stored XSS in WPBookit WordPress Plugin 1.0.1

Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit allows Stored XSS. This issue affects WPBookit: from n/a up to and including 1.0.1.

Solution

Update the WordPress WPBookit wordpress plugin to the latest available version (at least 1.0.2).
Vulnerable Product Search on Vulmon Subscribe to Product

iqonic design wpbookit

iqonicdesign wpbookit