Record summary

CVE-2026-1980 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails, phone numbers, dates of birth, and gender.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 4, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 1.0.8affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWPBookit <= 1.0.8 - Unauthenticated Customer Information DisclosureCVSS 5.3

WPBookit WordPress plugin <= 1.0.8 contains an information disclosure vulnerability caused by missing authorization check on 'get_customer_list' route, letting unauthenticated attackers retrieve sensitive customer data.

Impact

Unauthenticated attackers can access sensitive customer information, risking privacy and data exposure.

Remediation

Update to the latest version beyond 1.0.8.

WeaknessesCWE-200
Authorsaryu-ru
Template tagscvecve2026wordpresswp-pluginwpbookitunauthdisclosure
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
FOFA: body="/wp-content/plugins/wpbookit/"

Source: ProjectDiscovery

References

5