Skip to content

Known CVE

WPBookit <= 1.0.8 - Unauthenticated Customer Information Disclosure

WPBookit WordPress plugin <= 1.0.8 contains an information disclosure vulnerability caused by missing authorization check on 'get_customer_list' route, letting unauthenticated attackers retrieve sensitive customer data.

CVE-2026-1980

Medium2026CVSS 5.3CWE-200

cve2026 · wordpress · wp-plugin · wpbookit · unauth · disclosure

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website