Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

WPBookit plugin for WordPress exposes customer data without permission

CVE-2026-1980
Summary

The WPBookit plugin for WordPress doesn't properly check who can access customer information. This means unauthorized people can view sensitive customer data like names, emails, phone numbers, birthdays, and gender. Update the plugin to version 1.0.9 or later to fix this issue.

Original title
The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. Th...
Original description
The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails, phone numbers, dates of birth, and gender.
nvd CVSS3.1 5.3
Vulnerability type
CWE-200 Information Exposure
Published: 4 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026