
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1980 is an unauthorized data disclosure vulnerability in the WPBookit plugin for WordPress, caused by a missing authorization check on the get_customer_list route. It affects all versions of WPBookit up to and including 1.0.8, allowing unauthenticated attackers to retrieve sensitive customer data such as names, email addresses, phone numbers, dates of birth, and gender. The vulnerability was published on March 4, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, ENISA EUVD).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The get_customer_list route in the WPBookit plugin's admin class (class.wpb-admin-routes.php, line 146) does not perform any authorization or capability check before returning customer records, making it accessible to any unauthenticated HTTP request. An attacker can send a simple network request to this endpoint without any credentials or elevated privileges to retrieve the full customer list (Wordfence, WordPress Trac).
Successful exploitation results in unauthorized disclosure of sensitive personally identifiable information (PII) for all customers stored in the WPBookit system, including full names, email addresses, phone numbers, dates of birth, and gender. This data exposure could facilitate phishing campaigns, identity theft, or targeted social engineering attacks against affected customers. Integrity and availability of the WordPress site are not directly impacted by this vulnerability (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2026-1980. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of authentication requirements make it trivially exploitable by any unauthenticated attacker who can reach the WordPress site (Wordfence, ENISA EUVD).
https://target.com/wp-content/plugins/wpbookit/readme.txt.get_customer_list as registered in class.wpb-admin-routes.php.https://target.com/wp-admin/admin-ajax.php?action=get_customer_list or the equivalent REST endpoint) without any authentication headers or cookies.get_customer_list endpoint (e.g., admin-ajax.php?action=get_customer_list or equivalent REST route) from external IP addresses, especially in bulk or automated patterns.WordPress site administrators should update the WPBookit plugin to a version beyond 1.0.8 that includes the authorization fix, as reflected in the plugin changeset (WordPress Trac Changeset). If an immediate update is not possible, consider temporarily deactivating the WPBookit plugin or using a web application firewall (WAF) rule to block unauthenticated access to the get_customer_list route. Regularly audit installed WordPress plugins for missing authorization checks, particularly on routes that return customer or user data (Wordfence).
The vulnerability was discovered and reported by Wordfence, which published the advisory and coordinated disclosure. Automated CVE tracking accounts on Bluesky and Nitter noted the publication shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the initial Wordfence advisory has been identified (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."