cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-booking-system wp-booking-system

Direction: ascending
Jun 07, 2024

WP Booking System – Booking Calendar # CVE-2023-24402

CVE, Research URL

CVE-2023-24402

Date
Apr 07, 2023
Research Description
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18 versions.
Affected versions
max 2.0.18.1.
Status
vulnerable

WP Booking System &#8211; Booking Calendar # CVE-2021-25061

CVE, Research URL

CVE-2021-25061

Date
Jan 17, 2022
Research Description
The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.
Affected versions
max 2.0.15.
Status
vulnerable

WP Booking System &#8211; Booking Calendar # CVE-2019-12239

CVE, Research URL

CVE-2019-12239

Date
May 21, 2019
Research Description
The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
Affected versions
max 1.5.2.
Status
vulnerable

WP Booking System &#8211; Booking Calendar # CVE-2017-2168

CVE, Research URL

CVE-2017-2168

Date
May 22, 2017
Research Description
Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected versions
max 1.4.
Status
vulnerable
Jun 10, 2024

WP Booking System &#8211; Booking Calendar # CVE-2023-49758

CVE, Research URL

CVE-2023-49758

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in Veribo, Roland Murg WP Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Booking System: from n/a through 2.0.19.2.
Affected versions
max 2.0.19.3.
Status
vulnerable
Sep 15, 2024

WP Booking System &#8211; Booking Calendar # CVE-2024-8797

CVE, Research URL

CVE-2024-8797

Date
Sep 14, 2024
Research Description
The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.19.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.0.19.9.
Status
vulnerable
Oct 28, 2024

WP Booking System &#8211; Booking Calendar # CVE-2024-50425

CVE, Research URL

CVE-2024-50425

Date
Oct 30, 2024
Research Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Veribo, Roland Murg WP Booking System.This issue affects WP Booking System: from n/a through 2.0.19.10.
Affected versions
max 2.0.19.11.
Status
vulnerable
Mar 31, 2026

WP Booking System &#8211; Booking Calendar # CVE-2025-68515

CVE, Research URL

CVE-2025-68515

Date
Mar 05, 2026
Research Description
Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allows Retrieve Embedded Sensitive Data.This issue affects WP Booking System: from n/a through <= 2.0.19.12.
Affected versions
max 2.0.19.12.
Status
vulnerable