CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wpbookingcalendar 1Booking Calendar Feb 25, 2025 Feb 12, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verifi...Show more |
1Wpbookingcalendar 1Booking Calendar Nov 21, 2024 Jul 24, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions up to, and including, 10.2.1 due to insufficien...Show more |
1Wpbookingcalendar 1Booking Calendar Apr 8, 2026 Feb 8, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user...Show more |
1Wpbookingcalendar 1Booking Calendar Apr 28, 2026 Feb 1, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7...Show more |
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators |
1Wpbookingcalendar 1Booking Calendar Nov 21, 2024 Sep 6, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress leading to Translations Update. |