Wpbookingcalendar

Booking Calendar

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 12.02.2025 08:15:08
  • Zuletzt bearbeitet 25.02.2025 19:37:29

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has bee...

  • EPSS 0.25%
  • Veröffentlicht 24.07.2024 08:15:03
  • Zuletzt bearbeitet 21.11.2024 09:50:34

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions up to, and including, 10.2.1 due to insufficient input sanitization and outpu...

  • EPSS 75.58%
  • Veröffentlicht 08.02.2024 09:15:46
  • Zuletzt bearbeitet 21.11.2024 08:50:02

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack o...

  • EPSS 0.08%
  • Veröffentlicht 01.02.2024 12:15:54
  • Zuletzt bearbeitet 21.11.2024 08:38:17

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.

Exploit
  • EPSS 1.11%
  • Veröffentlicht 16.10.2023 09:15:11
  • Zuletzt bearbeitet 02.05.2025 18:15:25

The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators

  • EPSS 0.1%
  • Veröffentlicht 06.09.2022 18:15:15
  • Zuletzt bearbeitet 21.11.2024 07:07:39

Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress leading to Translations Update.