cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forbooking-ultra-pro booking-ultra-pro

Direction: ascending
Jun 07, 2024

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2021-36854

CVE, Research URL

CVE-2021-36854

Date
Sep 30, 2022
Research Description
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
Affected versions
Min -, max -.
Status
vulnerable

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2021-36855

CVE, Research URL

CVE-2021-36855

Date
Sep 30, 2022
Research Description
Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
Affected versions
Min -, max -.
Status
vulnerable

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2022-46816

CVE, Research URL

CVE-2022-46816

Date
May 24, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions.
Affected versions
Min -, max -.
Status
vulnerable

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2023-32236

CVE, Research URL

CVE-2023-32236

Date
Aug 23, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8 versions.
Affected versions
Min -, max -.
Status
vulnerable

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2024-32960

CVE, Research URL

CVE-2024-32960

Date
May 17, 2024
Research Description
Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.
Affected versions
Min -, max -.
Status
vulnerable

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2023-32511

CVE, Research URL

CVE-2023-32511

Date
Aug 24, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.8 versions.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2023-32601

CVE, Research URL

CVE-2023-32601

Date
Dec 13, 2024
Research Description
Missing Authorization vulnerability in Booking Ultra Pro Booking Ultra Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Ultra Pro: from n/a through 1.1.12.
Affected versions
Min -, max -.
Status
vulnerable
Jul 14, 2024

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2024-38676

CVE, Research URL

CVE-2024-38676

Date
Jul 20, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Booking Ultra Pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through 1.1.13.
Affected versions
Min -, max -.
Status
vulnerable

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2024-38717

CVE, Research URL

CVE-2024-38717

Date
Jul 12, 2024
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows PHP Local File Inclusion.This issue affects Booking Ultra Pro: from n/a through 1.1.13.
Affected versions
Min -, max -.
Status
vulnerable
Jul 18, 2024

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2024-6175

CVE, Research URL

CVE-2024-6175

Date
Jul 18, 2024
Research Description
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions in all versions up to, and including, 1.1.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify and delete. multiple plugin options and data such as payments, pricing, booking information, business hours, calendars, profile information, and email templates.
Affected versions
Min -, max -.
Status
vulnerable
Mar 01, 2025

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2025-27345

CVE, Research URL

CVE-2025-27345

Date
Apr 17, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Reflected XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.19.
Affected versions
Min -, max -.
Status
vulnerable
Jun 15, 2025

Booking Ultra Pro Appointments Booking Calendar Plugin # CVE-2025-30637

CVE, Research URL

CVE-2025-30637

Date
Jun 06, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Stored XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.20.
Affected versions
Min -, max -.
Status
vulnerable