CVE-2025-4669
- EPSS 0.07%
- Veröffentlicht 17.05.2025 11:17:17
- Zuletzt bearbeitet 04.06.2025 20:10:00
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attrib...
CVE-2024-13323
- EPSS 0.05%
- Veröffentlicht 14.01.2025 06:15:15
- Zuletzt bearbeitet 12.08.2025 16:01:46
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied at...
CVE-2024-10893
- EPSS 0.08%
- Veröffentlicht 03.12.2024 06:15:08
- Zuletzt bearbeitet 17.05.2025 01:49:51
The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ...
CVE-2024-10027
- EPSS 0.02%
- Veröffentlicht 07.11.2024 06:15:13
- Zuletzt bearbeitet 15.05.2025 17:19:09
The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabi...
CVE-2024-9306
- EPSS 0.09%
- Veröffentlicht 04.10.2024 07:15:03
- Zuletzt bearbeitet 08.10.2024 16:25:29
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticat...
CVE-2024-8274
- EPSS 0.94%
- Veröffentlicht 30.08.2024 10:15:08
- Zuletzt bearbeitet 03.09.2024 14:28:06
The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5 due to insufficient input sanitization and output escaping. This makes ...