CVE-2026-73395
- EPSS 0.32%
- Veröffentlicht 18.08.2026 14:00:32
- Zuletzt bearbeitet 20.08.2026 12:48:31
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
CVE-2026-8840
- EPSS 0.32%
- Veröffentlicht 15.08.2026 02:26:16
- Zuletzt bearbeitet 20.08.2026 12:48:10
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action....
CVE-2026-57778
- EPSS 0.21%
- Veröffentlicht 13.07.2026 08:41:25
- Zuletzt bearbeitet 13.07.2026 17:18:03
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: fro...
CVE-2026-15289
- EPSS 0.35%
- Veröffentlicht 10.07.2026 04:31:23
- Zuletzt bearbeitet 10.07.2026 15:43:30
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpdevart_id’ parameter in all versions up to, and including, 3.2.17 due to insufficient escaping on the user supplied parameter a...
CVE-2026-25435
- EPSS 0.18%
- Veröffentlicht 25.03.2026 16:14:49
- Zuletzt bearbeitet 24.04.2026 16:35:20
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Stored XSS.This issue affects Booking calendar, Appointment Booking Sy...
CVE-2025-67574
- EPSS 0.25%
- Veröffentlicht 09.12.2025 14:14:13
- Zuletzt bearbeitet 27.04.2026 18:16:43
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: fro...
CVE-2024-12077
- EPSS 0.37%
- Veröffentlicht 07.01.2025 08:15:24
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘calendar_id’ parameter in all versions up to, and including, 3.2.19 and 11.2.19 respectively, due to insufficient input sani...
CVE-2024-10856
- EPSS 0.49%
- Veröffentlicht 24.12.2024 11:15:07
- Zuletzt bearbeitet 21.03.2025 18:50:57
The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpdevart_booking_calendar” shortcode in versions up to, and including, 3.2.19 due to insufficient escaping on the user-supplied param...
CVE-2023-24407
- EPSS 0.49%
- Veröffentlicht 09.12.2024 13:15:22
- Zuletzt bearbeitet 28.04.2026 19:19:40
Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2...
CVE-2024-9504
- EPSS 0.46%
- Veröffentlicht 26.11.2024 08:15:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This make...