Vulnerabilities and security researches forwp-booking-system wp-booking-system
Direction: descendingMar 31, 2026
WP Booking System – Booking Calendar # CVE-2025-68515
- CVE, Research URL
- Application
- Date
- Mar 05, 2026
- Research Description
- Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allows Retrieve Embedded Sensitive Data.This issue affects WP Booking System: from n/a through <= 2.0.19.12.
- Affected versions
-
max 2.0.19.12.
- Status
-
vulnerable
Oct 28, 2024
WP Booking System – Booking Calendar # CVE-2024-50425
- CVE, Research URL
- Application
- Date
- Oct 30, 2024
- Research Description
- Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Veribo, Roland Murg WP Booking System.This issue affects WP Booking System: from n/a through 2.0.19.10.
- Affected versions
-
max 2.0.19.11.
- Status
-
vulnerable
Sep 15, 2024
WP Booking System – Booking Calendar # CVE-2024-8797
- CVE, Research URL
- Application
- Date
- Sep 14, 2024
- Research Description
- The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.19.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 2.0.19.9.
- Status
-
vulnerable
Jun 10, 2024
WP Booking System – Booking Calendar # CVE-2023-49758
- CVE, Research URL
- Application
- Date
- Dec 09, 2024
- Research Description
- Missing Authorization vulnerability in Veribo, Roland Murg WP Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Booking System: from n/a through 2.0.19.2.
- Affected versions
-
max 2.0.19.3.
- Status
-
vulnerable
Jun 07, 2024
WP Booking System – Booking Calendar # CVE-2023-24402
- CVE, Research URL
- Application
- Date
- Apr 07, 2023
- Research Description
- Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18 versions.
- Affected versions
-
max 2.0.18.1.
- Status
-
vulnerable
WP Booking System – Booking Calendar # CVE-2021-25061
- CVE, Research URL
- Application
- Date
- Jan 17, 2022
- Research Description
- The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.
- Affected versions
-
max 2.0.15.
- Status
-
vulnerable
WP Booking System – Booking Calendar # CVE-2019-12239
- CVE, Research URL
- Application
- Date
- May 21, 2019
- Research Description
- The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
- Affected versions
-
max 1.5.2.
- Status
-
vulnerable
WP Booking System – Booking Calendar # CVE-2017-2168
- CVE, Research URL
- Application
- Date
- May 22, 2017
- Research Description
- Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected versions
-
max 1.4.
- Status
-
vulnerable