WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function

CVE Details

Basic Information

Title WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function
Type cve
Published 2025-07-24T04:24:12.852Z
Modified 2025-07-24T04:24:12.852Z

Product Information

Vendor iqonicdesign
Product WPBookit
Version *

CVSS Information

Base Score 9.8 (CRITICAL)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Analysis

AI Description The WPBookit WordPress plugin allows arbitrary file uploads due to insufficient validation, enabling unauthenticated attackers to upload malicious files, potentially leading to remote code execution.
AI Severity Critical
AI Vendor WordPress Community
AI Product WPBookit
AI Version 1.0.6

Affected Products

  • iqonicdesign WPBookit *

Additional Information

CWE List CWE-434
Source Wordfence

Description

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the ‘add_new_customer’ route in all versions up to, and including, 1.0.6. The plugin’s image-upload handler calls move_uploaded_file() on client-supplied files without restricting allowed extensions or MIME types, nor sanitizing the filename. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site’s server which may make remote code execution possible.

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.