CVE-2025-26910: WordPress WPBookit plugin <= 1.0.1 - Cross Site Request Forgery (CSRF) Vulnerability
Published Mar 10, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <= 1.0.1.
Affected Software
3 affected components
Iqonic Design WPBookit<=1.0.1
WordPress WPBookit<=1.0.1
Iqonic Wpbookit Wordpress<1.0.2
Remediation
Information
Update the WordPress WPBookit wordpress plugin to the latest available version (at least 1.0.2).
Event History
Mar 10, 2025
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26910?
CVE-2025-26910 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How can I fix CVE-2025-26910?
To fix CVE-2025-26910, upgrade WPBookit to the latest version that mitigates the vulnerability.
3
What specific versions are affected by CVE-2025-26910?
CVE-2025-26910 affects WPBookit versions up to and including 1.0.1.
4
What type of vulnerability is CVE-2025-26910?
CVE-2025-26910 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Stored XSS.
5
Who is the vendor associated with CVE-2025-26910?
The vendor associated with CVE-2025-26910 is Iqonic Design, the developer of WPBookit.