← Vulnerability feed

Vulnerability record · CVE-2025-6058 · published 12 July 2025

CVE-2025-6058: Iqonic wpbookit unrestricted file upload vulnerability

Iqonic · Wpbookit

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

9.8 CVSS 3.1 Critical EPSS 5.5% · top 7.4% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-6058 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-3810Iqonic wpbookit insecure direct object reference vulnerabilityThe WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due…EPSS 0.72%9.8CVE-2025-3811Iqonic wpbookit insecure direct object reference vulnerabilityThe WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due…EPSS 0.72%9.8CVE-2025-0357Iqonic wpbookit unrestricted file upload vulnerabilityThe WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::ha…EPSS 1.1%9.8CVE-2024-10215Iqonic wpbookit insecure direct object reference vulnerabilityThe WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin …EPSS 0.66%9.8CVE-2024-54280Iqonic wpbookit sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Inje…EPSS 0.63%8.8CVE-2025-6057Iqonic wpbookit unrestricted file upload vulnerabilityThe WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function i…EPSS 0.66%6.1CVE-2025-26910Iqonic wpbookit cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <=…EPSS 0.14%5.3CVE-2025-32254Iqonic wpbookit missing authorization vulnerabilityMissing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2025-6058), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.