Critical severity9.8NVD Advisory· Published Jan 9, 2025· Updated Jun 17, 2026
CVE-2024-10215
CVE-2024-10215
Description
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=1.6.4+ 1 more
- (no CPE)range: <=1.6.4
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/2d23a2b9-8476-4564-a5de-5e6cfc38ce68nvdThird Party Advisory
- documentation.iqonic.design/wpbookit/versions/change-lognvdRelease Notes
News mentions
0No linked articles in our index yet.