PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jul 21, 2026

WPBookit <= 1.0.8 - Unauthenticated Customer Information Disclosure

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-1980
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails, phone numbers, dates of birth, and gender.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WPBookitby iqonicdesign
0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

WPBookit <= 1.0.8 - Unauthenticated Customer Information Disclosure CVE-2026-1980 Scanner | S4E