Ba-booking

Ba Book Everything

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 06.10.2024 10:15:04
  • Zuletzt bearbeitet 23.04.2026 15:19:14

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bookingalgorithms BA Book Everything ba-book-everything.This issue affects BA Book Everything: from n/a through <= 1.6.20.

  • EPSS 0.42%
  • Veröffentlicht 24.09.2024 03:15:03
  • Zuletzt bearbeitet 26.09.2024 16:23:46

The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a user's identity prior to setting a password. This ma...

  • EPSS 0.29%
  • Veröffentlicht 24.09.2024 02:15:04
  • Zuletzt bearbeitet 26.09.2024 16:46:55

The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to missing or incorrect nonce validation on the my_account_update() function. This makes it possible for...

  • EPSS 0.29%
  • Veröffentlicht 18.04.2024 10:15:12
  • Zuletzt bearbeitet 28.04.2026 19:24:48

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.

  • EPSS 0.33%
  • Veröffentlicht 18.04.2024 09:15:14
  • Zuletzt bearbeitet 28.04.2026 19:24:50

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.

  • EPSS 0.32%
  • Veröffentlicht 16.04.2024 13:15:11
  • Zuletzt bearbeitet 08.04.2026 19:21:25

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'all-items' shortcode in all versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping on user supplied at...

  • EPSS 0.58%
  • Veröffentlicht 15.04.2024 08:15:13
  • Zuletzt bearbeitet 28.04.2026 19:24:35

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.