← Vulnerability feed

Vulnerability record · CVE-2024-10215 · published 9 January 2025

CVE-2024-10215: Iqonic wpbookit insecure direct object reference vulnerability

Iqonic · Wpbookit

The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

9.8 CVSS 3.1 Critical EPSS 0.66% · top 50.2% CWE-639 · Insecure direct object reference
9.8CVSS 3.1 base score
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-10215 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-6058Iqonic wpbookit unrestricted file upload vulnerabilityThe WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function h…EPSS 5.5%9.8CVE-2025-3810Iqonic wpbookit insecure direct object reference vulnerabilityThe WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due…EPSS 0.72%9.8CVE-2025-3811Iqonic wpbookit insecure direct object reference vulnerabilityThe WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due…EPSS 0.72%9.8CVE-2025-0357Iqonic wpbookit unrestricted file upload vulnerabilityThe WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::ha…EPSS 1.1%9.8CVE-2024-54280Iqonic wpbookit sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Inje…EPSS 0.63%8.8CVE-2025-6057Iqonic wpbookit unrestricted file upload vulnerabilityThe WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function i…EPSS 0.66%6.1CVE-2025-26910Iqonic wpbookit cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <=…EPSS 0.14%5.3CVE-2025-32254Iqonic wpbookit missing authorization vulnerabilityMissing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2024-10215), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.