CVE-2026-1980Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails, phone numbers, dates of birth, and gender.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-04); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-04: 4Mentions · 2026-07-21: 1Technical Details · 2026-03-04: 3Technical Details · 2026-07-21: 103-0407-21
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-044
Disclosure3General1
2026-07-211
Disclosure1
Full discourse5 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1980 - medium 🚨 WPBookit <= 1.0.8 - Unauthenticated Customer Information Disclosure > WPBookit WordPress plugin <= 1.0.8 contains an information disclosure vulnerability c... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1980 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2026‑1980 as an unauthenticated customer information disclosure in WPBookit <=1.0.8, but provides no PoC, exploit, or mitigation details.

    00011294
    1.1K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-1980 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1980 #CVE-2026-1980 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/hWaHZibLJG

    Post summary

    The tweet merely announces a new WordPress CVE with its medium severity rating and a reference link, but offers no further technical or mitigation information.

    0000045
    64 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1980 The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up… https://www.cve.org/CVERecord?id=CVE-2026-1980 ----- Traducción: CVE-2026-1980 El … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-1980, describing an unauthorized data disclosure flaw in WPBookit’s get_customer_list route, but provides no PoC, exploit, or patch details.

    0000029
    55 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1980 Unauthenticated Customer Data Disclosure in WPBookit WordP... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1980 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A new unauthenticated customer data disclosure vulnerability (CVE-2026-1980) in the WPBookit WordPress plugin has been announced, with a link to details but no PoC, exploit, or patch information provided.

    0000053
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1980 The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up… https://www.cve.org/CVERecord?id=CVE-2026-1980

    Post summary

    The WPBookit plugin for WordPress has a missing authorization check on the 'get_customer_list' route, leading to unauthorized data disclosure (CVE-2026-1980).

    00000520
    56.6K followersView on X

Explore more