Known vulnerabilities in WPBookit
WPBookit is a free WordPress booking plugin that simplifies seamless scheduling, custom calendars and global accessibility.
14Reported vulnerabilities
9.8Highest CVSS score
1.0.9Latest version
10+Active installs
What to do now
Update WPBookit to 1.0.9 or later.
12 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-6058 | Critical | 5.5% | 0 to 1.0.4 (inclusive) | 1.0.5 |
July 12, 2025 |
| CVE-2025-7852 | Critical | 1.5% | 0 to 1.0.6 (inclusive) | 1.0.7 |
July 24, 2025 |
| CVE-2025-0357 | Critical | 1.1% | 1.6.9 and earlier | 1.6.10 |
January 24, 2025 |
| CVE-2025-3811 | Critical | 0.7% | 0 to 1.0.2 (inclusive) | 1.0.3 |
May 9, 2025 |
| CVE-2025-3810 | Critical | 0.7% | 0 to 1.0.2 (inclusive) | 1.0.3 |
May 9, 2025 |
| CVE-2024-10215 | Critical | 0.7% | 1.6.4 and earlier | 1.6.6 |
January 9, 2025 |
| CVE-2025-6057 | High | 0.7% | 0 to 1.0.4 (inclusive) | 1.0.5 |
July 12, 2025 |
| CVE-2024-54280 | High | 0.6% | 1.6.0 and earlier | — | December 11, 2024 |
| CVE-2026-1945 | High | 0.3% | 0 to 1.0.8 (inclusive) | 1.0.9 |
March 4, 2026 |
| CVE-2025-12135 | High | 0.3% | 0 to 1.0.6 (inclusive) | 1.0.7 |
November 21, 2025 |
| CVE-2025-26910 | Medium | 0.1% | 1.0.1 and earlier | 1.0.2 |
March 9, 2025 |
| CVE-2026-1980 | Medium | 0.8% | 0 to 1.0.8 (inclusive) | 1.0.9 |
March 4, 2026 |
| CVE-2025-32254 | Medium | 0.4% | 1.0.7 and earlier | 1.0.8 |
April 4, 2025 |
| CVE-2025-12685 | Medium | 0.2% | 1.0.7 and earlier | — | December 12, 2025 |