The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.
History

Fri, 02 Jan 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.
Title WPBookit <= 1.0.7 - Customer Deletion via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-01-02T06:00:10.447Z

Reserved: 2025-11-04T05:28:26.059Z

Link: CVE-2025-12685

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-02T06:15:53.283

Modified: 2026-01-02T06:15:53.283

Link: CVE-2025-12685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.