CVE-2026-1980
WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure
Record summary
CVE-2026-1980 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails, phone numbers, dates of birth, and gender.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WPBookitBrowse iqonicdesign / WPBookitDefault status: unaffected | CVE List | Through 1.0.8 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWPBookit <= 1.0.8 - Unauthenticated Customer Information DisclosureCVSS 5.3
WPBookit WordPress plugin <= 1.0.8 contains an information disclosure vulnerability caused by missing authorization check on 'get_customer_list' route, letting unauthenticated attackers retrieve sensitive customer data.
Impact
Unauthenticated attackers can access sensitive customer information, risking privacy and data exposure.
Remediation
Update to the latest version beyond 1.0.8.
Source: ProjectDiscovery