Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Drtime

#21014of 53,624
11.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-1050
6.5
2026-01-02
WordPress · Wpbookit · CVE-2025-12685
**Name of the Vulnerable Software and Affected Versions** WPBookit versions through 1.0.7 **Description** The WPBookit WordPress plugin does not properly validate Cross-Site Request Forgery (CSRF) tokens when deleting customer data. This allows an attacker, without needing to be logged in, to delete any customer record by exploiting a CSRF attack. The vulnerable operation involves deleting customers. **Recommendations** Update WPBookit to a version later than 1.0.7.
PT-2025-54283
5.3
2025-12-31
WordPress · The Ultimate Post Kit Addons For Elementor · CVE-2025-14434
**Name of the Vulnerable Software and Affected Versions** The Ultimate Post Kit Addons for Elementor WordPress plugin versions prior to 4.0.16 **Description** The plugin has multiple AJAX “load more” endpoints, including `upk alex grid loadmore posts`, that do not properly verify post publication status before displaying content. This allows attackers without authentication to access and retrieve rendered HTML content of private and unpublished posts. **Recommendations** Update to version 4.0.16 or later.