Pinpoint Booking System – Version 2

Pinpoint Booking System – Version 2 has 16 disclosed vulnerabilities in the WordSec catalog, reported between 2013 and 2026; 13 are fixed and 3 remain unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 4 high. 2024 was the busiest year with 5 disclosures.

The most common weakness is SQL Injection, behind 7 of the records (44%). Other recurring categories include Cross-Site Scripting, Cross-Site Request Forgery (CSRF).

13 of the records (81%) have a vendor fix, while 3 remain unpatched. The oldest unresolved one dates back to 2026.

12 independent researchers contributed these findings, most of them (2) reported by Muhammad Daffa.

01234567891004.07.2013Today04.07.20136.1Pinpoint Booking System – #1 WordPress Booking Plugin <= 1.3.1 - Reflected Cross-Site Scripting CVSS 6.1 · 04.07.201321.05.20148.8Pinpoint Booking System – #1 WordPress Booking Plugin < 1.3 - SQL Injection CVSS 8.8 · 21.05.201407.07.20158.8Pinpoint Booking System – #1 WordPress Booking Plugin < 2.1 - Authenticated SQL Injection CVSS 8.8 · 07.07.201523.01.20238.8Pinpoint Booking System <= 2.9.9.2.8 - Authenticated (Subscriber+) SQL Injection CVSS 8.8 · 23.01.202302.02.20234.4Pinpoint Booking System <= 2.9.9.2.8 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 02.02.202320.07.20235.3Pinpoint Booking System <= 2.9.9.3.4 - Content Spoofing CVSS 5.3 · 20.07.202306.10.20235.4Pinpoint Booking System <= 2.9.9.4.0 - Cross-Site Request Forgery via initBackEndAJAX CVSS 5.4 · 06.10.202315.07.20244.4Pinpoint Booking System <= 2.9.9.4.7 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 15.07.202406.09.20248.8Pinpoint Booking System <= 2.9.9.5.0- Authenticated (Subscriber+) SQL Injection CVSS 8.8 · 06.09.202415.10.20246.1Pinpoint Booking System <= 2.9.9.5.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting CVSS 6.1 · 15.10.202402.12.20246.5Pinpoint Booking System <= 2.9.9.5.1 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 02.12.202405.12.20246.3Pinpoint Booking System – #1 WordPress Booking Plugin <= 2.9.9.5.7 - Missing Authorization CVSS 6.3 · 05.12.202420.02.20256.5Pinpoint Booking System – #1 WordPress Booking Plugin <= 2.9.9.5.4 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 20.02.202520.02.20265.3Pinpoint Booking System <= 2.9.9.6.5 - Missing Authorization CVSS 5.3 · 20.02.202631.07.20264.9Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Injection via 'field' Parameter CVSS 4.9 · 31.07.202614.08.20265.3Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter CVSS 5.3 · 14.08.2026

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage81%
Open

3

Fixed

13

Get automatic notifications for all Pinpoint Booking System – Version 2 vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2026-12128

Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter

Read the full analysis

Vulnerability Records

16 records
2026-08-14 14:05CVE-2026-12128
5.3
Medium
Enrico MarcoliniNo
2026-07-31 12:40CVE-2026-15403
4.9
Medium
Wordfence PRISMNo
2026-02-20 00:00CVE-2026-39678
5.3
Medium
Quan RealmeNo
2025-02-20 15:05CVE-2024-13235
6.5
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2024-12-05 00:00CVE-2024-54252
6.3
Medium
Muhammad DaffaYes
2024-12-02 00:00CVE-2024-53815
6.5
Medium
Trương Hữu Phúc (truonghuuphuc)Yes
2024-10-15 00:00CVE-2024-49304
6.1
Medium
Muhammad DaffaYes
2024-09-06 23:03CVE-2024-7112
8.8
High
Piotr KuśpitYes
2024-07-15 00:00CVE-2024-3636
4.4
Medium
cyc707Yes
2023-10-06 00:00CVE-2023-45270
5.4
Medium
Kévin Mosbahi (Mika)Yes
Showing 1–10 of 16 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C