CVE-2025-26910
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 10, 2025
CWE ID 352
Summary
CVE-2025-26910 is a Cross-Site Request Forgery (CSRF) vulnerability identified in Iqonic Design's WPBookit plugin. This issue permits an attacker to perform malicious actions on a user's behalf, including executing Stored Cross-Site Scripting (XSS) attacks. The vulnerability affects WPBookit versions from n/a through 1.0.1. Successful exploitation could result in unintended actions, such as account takeover or data theft. Users are strongly recommended to update WPBookit to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.