iqonicdesign Vulnerabilities and Affected Products
Vulnerabilities associated with WPBookit Pro.
Products
Clear product- KiviCare – Clinic & Patient Management System (EHR)10 vulnerabilities
- WPBookit8 vulnerabilities
- Graphina – Charts and Graphs For Elementor3 vulnerabilities
- Streamit3 vulnerabilities
- WPBookit Pro3 vulnerabilities
- SocialV - Social Network and Community BuddyPress Theme1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-25414HIGH | WordPress WPBookit Pro plugin <= 1.6.18 - Privilege Escalation vulnerabilityIncorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through <= 1.6.18. CWE-266Mar 25, 2026 | CVSS8.8v3.1 | EPSS0.286% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25413CRITICAL | WordPress WPBookit Pro plugin <= 1.6.18 - Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18. CWE-434Mar 25, 2026 | CVSS9.9v3.1 | EPSS0.328% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25415MEDIUM | WordPress WPBookit Pro plugin <= 1.6.18 - Broken Access Control vulnerabilityMissing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18. CWE-862Feb 19, 2026 | CVSS5.3v3.1 | EPSS0.214% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |