Description
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
Any version
Timeline
| 2025-06-14: | Vendor Notified |
| 2025-07-11: | Disclosed |
Credits
Youcef Hamdani
References
www.wordfence.com/...-c6c9-4009-aacb-52adc70c0261?source=cve
plugins.trac.wordpress.org/...ass.wpb-profile-controller.php
wordpress.org/plugins/wpbookit/
plugins.trac.wordpress.org/...wpbookit&sfp_email=&sfph_mail=