PT-2025-29294 · WordPress · Wpbookit

Matthew Rollings

·

Published

2025-07-12

·

Updated

2025-07-22

·

CVE-2025-6058

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPBookit versions up to and including 1.0.4
Description The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image upload handle() function, which is triggered via the '/add booking type' route. This allows unauthenticated attackers to upload arbitrary files to the affected site's server, potentially leading to remote code execution.
Recommendations WPBookit versions up to and including 1.0.4: Update to version 1.0.5 or later to address the issue.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-6058

Affected Products

Wpbookit