PoC Index

CVE-2026-1980

MEDIUM 5.3EPSS 0.8%

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails, phone numbers, dates of birth, and gender.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.83% chance of exploitation in the next 30 days, 55th percentile
Nuclei
medium · CWE-200
Published
2026-03-04
Updated
2026-04-08

Nuclei templates (1)

References

Related