CVE-2026-1980 Scanner
CVE-2026-1980 Scanner - Information Disclosure vulnerability in WPBookit
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
16 days 18 hours
Scan only one
Domain, Subdomain, IPv4
Toolbox
The WPBookit plugin is typically utilized by Wordpress users, specifically in WordPress sites aimed at managing bookings and appointments. It is particularly relevant for businesses that offer services requiring reservation, such as hotels and spas. Developers aimed at enhancing the booking capabilities of WordPress functionalities often install it. The plugin helps site owners track, manage, and coordinate bookings in an efficient manner directly from the WordPress admin panel. WPBookit's integration with WordPress offers seamless interactivity for users seeking increased functionality. As such, ensuring the security of the plugin is crucial for maintaining the confidentiality of user information.
The Information Disclosure vulnerability found in WPBookit allows unauthorized access to potentially sensitive customer data. This vulnerability arises due to ineffective authorization control over plugin routes. Attackers can exploit this weakness to extract confidential information meant to be private. Till the version 1.0.8, this vulnerability persisted due to the missing authorization checks on critical access points. By abusing this loophole, attackers can compromise user data, leading to privacy breaches. Consequently, the presence of this vulnerability significantly undermines data security.
This Information Disclosure vulnerability in WPBookit is notably connected to the 'get_customer_list' route. The lack of proper authorization checks on this endpoint permits unauthenticated users to retrieve sensitive information. By sending crafted HTTP requests to this endpoint, attackers can extract user data without credentials. The vulnerability was seen in WPBookit versions up to 1.0.8, where it left both user and customer data at risk. Due to the unchecked nature of the endpoint, attackers can potentially automate attacks for larger data extraction efficiently. This overlooked flaw represents a serious risk to data integrity and privacy.
Exploiting this vulnerability could have serious consequences for affected users. Confidential customer information such as personal details or booking data may become publicly accessible. The leak could compromise users' privacy and lead to unauthorized use of their data. Furthermore, this vulnerability could harm the business reputation of affected entities by showcasing negligence in their data security practices. In severe cases, attackers may use the disclosed information for further cyber-attacks or identity theft. The exposure risks involved necessitate immediate corrections to maintain data safety.
REFERENCES
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a1867c79-29d7-46a4-bfaf-c65e8a44c2ed?source=cve
- https://plugins.trac.wordpress.org/browser/wpbookit/tags/1.0.8/core/admin/classes/class.wpb-admin-routes.php#L146
- https://nvd.nist.gov/vuln/detail/CVE-2026-1980
- https://wordpress.org/plugins/wpbookit/