WPBookit

WPBookit has 14 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; 12 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 7.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 6 critical and 4 high. 2025 was the busiest year with 11 disclosures.

The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 4 of the records (29%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Cross-Site Request Forgery (CSRF).

12 of the records (86%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2024.

10 independent researchers contributed these findings, most of them (2) reported by István Márton. WPBookit is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

01234567891018.12.2024Today11.12.20247.5WPBookit <= 1.6.0 - Unauthenticated SQL Injection CVSS 7.5 · 11.12.202409.01.20259.8WPBookit <= 1.6.4 - Unauthenticated Arbitrary User Password Change CVSS 9.8 · 09.01.202524.01.20259.8WPBookit <= 1.6.9 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 24.01.202509.03.20256.1WPBookit <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting CVSS 6.1 · 09.03.202504.04.20255.3WPBookit <= 1.0.7 - Missing Authorization CVSS 5.3 · 04.04.202508.05.20259.8WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover CVSS 9.8 · 08.05.20259.8WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Email Update CVSS 9.8 · 08.05.202511.07.20259.8WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 11.07.20258.8WPBookit <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 11.07.202523.07.20259.8WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function CVSS 9.8 · 23.07.202520.11.20257.2WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 20.11.202512.12.20254.3WPBookit <= 1.0.7 - Cross-Site Request Forgery to Customer Deletion CVSS 4.3 · 12.12.202503.03.20265.3WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure CVSS 5.3 · 03.03.20267.2WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters CVSS 7.2 · 03.03.2026

Strategic Overview

Avg CVSSHigh
7.9/ 10
Patch Coverage86%
Open

2

Fixed

12

Get automatic notifications for all WPBookit vulnerabilities before they are exploited.

Most severe open issueCVSS 7.5CVE-2024-54280

WPBookit <= 1.6.0 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

14 records
2026-03-03 12:30CVE-2026-1945
7.2
High
MD. TAREQ AHAMED JONY (itztrq)Yes
2026-03-03 12:28CVE-2026-1980
5.3
Medium
MD. TAREQ AHAMED JONY (itztrq)Yes
2025-12-12 00:00CVE-2025-12685
4.3
Medium
DrtimeNo
2025-11-20 18:42CVE-2025-12135
7.2
High
Ryan KozakYes
2025-07-23 16:22CVE-2025-7852
9.8
Critical
theviper17yYes
2025-07-11 00:00CVE-2025-6058
9.8
Critical
stealthcopterYes
2025-07-11 00:00CVE-2025-6057
8.8
High
theviper17yYes
2025-05-08 00:00CVE-2025-3810
9.8
Critical
kr0dYes
2025-05-08 00:00CVE-2025-3811
9.8
Critical
kr0dYes
2025-04-04 00:00CVE-2025-32254
5.3
Medium
Pham Van TamYes
Showing 1–10 of 14 reports
WPBookit banner
Latestv1.0.9
0.0(0)
0/100
Last Updated
2026-02-23 (7mo ago)
Active Installs
10+
Downloads
4,737
Requires WP
3.0.1+
Requires PHP
8.0+
Tested up to
WP 6.9.7
Created
2024-12-18 (2y ago)

Streamline your appointment booking process with WPBookit, the ultimate free appointment booking WordPress plugin. Ideal for businesses of all sizes, WPBookit offers a comprehensive suite of features designed to simplify scheduling, enhance user experience, and boost productivity. Features: Revenue Chart Report: Gain valuable insights into your earnings with detailed revenue charts. Booking Calendar/List View: View and manage bookings effortlessly with both calendar and list views. Different Calendars for Different Services: Organize your services with separate calendars for each one. Custom Time Slots: Customize available time slots to fit your unique business hours and needs. Calendar-wise Unavailable Dates: Mark unavailable dates on individual calendars to avoid scheduling conflicts. Guest Users List: Maintain a list of guest users for easy reference and follow-up. Easy Email Template Editing: Customize email templates with ease for a personalized communication experience. Translation Ready: Cater to a global audience with translation-ready capabilities. Benefits: Efficient Scheduling: Simplify the booking process with intuitive calendar and list views, ensuring smooth management of appointments. Enhanced User Experience: Provide a seamless experience for both customers and staff with features like custom timeslots, email notifications. Virtual Consultations: Offer convenient telemedicine services with Zoom integration, expanding your reach and flexibility. Comprehensive Management: Keep track of guest users, manage multiple services, and generate detailed reports to optimize your business operations. Global Reach: Serve a diverse audience with translation-ready functionality, making your services accessible to users worldwide. Elevate your appointment booking process with WPBookit – the free WordPress plugin designed to meet all your scheduling needs. WPBookit Pro version is also available with advance featutes. Source Code The original, non-minified source code for the JavaScript and CSS files used in this plugin can be found in the core/admin/assets/src directory of the plugin folder. External Services WPBookit interacts with external services to enhance functionality and provide accurate data. Services Used: ipapi.co (https://ipapi.co/) Purpose: Used for geolocation purposes to automatically determine and set the user’s country based on their IP address. Terms of Use: ipapi.co Terms of Service Privacy Policy: ipapi.co Privacy Policy Google Fonts (https://fonts.googleapis.com/) Purpose: The plugin uses the “Plus Jakarta Sans” font, which is loaded from Google Fonts to enhance the visual appearance of the plugin. Terms of Use: Google Fonts Terms of Service Privacy Policy: Google Fonts Privacy Policy Add to Calendar Pro API (https://add-to-calendar-pro.com/) Purpose: Used to add booking details directly to users’ calendars. Terms of Use: Add to Calendar Pro Terms of Service Privacy Policy: Add to Calendar Pro Privacy Policy By using WPBookit, you agree to the terms and conditions outlined by these external services.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C