First published: Mon Mar 10 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit allows Stored XSS. This issue affects WPBookit: from n/a through 1.0.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPBookit | <=1.0.1 | |
WPBookit | <=1.0.1 |
Update the WordPress WPBookit wordpress plugin to the latest available version (at least 1.0.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26910 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2025-26910, upgrade WPBookit to the latest version that mitigates the vulnerability.
CVE-2025-26910 affects WPBookit versions up to and including 1.0.1.
CVE-2025-26910 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Stored XSS.
The vendor associated with CVE-2025-26910 is Iqonic Design, the developer of WPBookit.