CVE-2024-47360
- EPSS 0.15%
- Veröffentlicht 06.10.2024 10:15:04
- Zuletzt bearbeitet 13.03.2025 13:44:38
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Reflected XSS.This issue affects BA Book Everything: from n/a through 1.6.20.
CVE-2024-8794
- EPSS 0.38%
- Veröffentlicht 24.09.2024 03:15:03
- Zuletzt bearbeitet 26.09.2024 16:23:46
The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a user's identity prior to setting a password. This ma...
CVE-2024-8795
- EPSS 0.38%
- Veröffentlicht 24.09.2024 02:15:04
- Zuletzt bearbeitet 26.09.2024 16:46:55
The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to missing or incorrect nonce validation on the my_account_update() function. This makes it possible for...
CVE-2024-32576
- EPSS 0.14%
- Veröffentlicht 18.04.2024 10:15:12
- Zuletzt bearbeitet 12.03.2025 18:44:43
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.
CVE-2024-32598
- EPSS 0.12%
- Veröffentlicht 18.04.2024 09:15:14
- Zuletzt bearbeitet 12.03.2025 18:50:00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.
CVE-2024-3672
- EPSS 0.18%
- Veröffentlicht 16.04.2024 13:15:11
- Zuletzt bearbeitet 12.03.2025 18:51:24
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'all-items' shortcode in all versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping on user supplied at...
CVE-2024-32125
- EPSS 0.33%
- Veröffentlicht 15.04.2024 08:15:13
- Zuletzt bearbeitet 12.03.2025 18:52:52
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.