Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.3
WPBookit Pro: Insecure Access Control Lets Hackers Access Sensitive Data
CVE-2026-25415
Summary
If the access control settings are not properly configured in WPBookit Pro, an attacker could access sensitive information or perform actions they shouldn't be able to. This is a concern for websites using WPBookit Pro versions 1.6.18 and earlier. To fix this, update to a newer version of WPBookit Pro or adjust the access control settings to ensure they are secure.
Original title
Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a throu...
Original description
Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18.
nvd CVSS3.1
5.3
Vulnerability type
CWE-862
Missing Authorization
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026