Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress

Explore Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress vulnerabilities across all versions. Currently tracking 18 known vulnerabilities, including severity, impact, and patch status.

01234567891028.02.2022Today28.02.20229.8BookingPress < 1.0.11 - SQL Injection CVSS 9.8 · 28.02.202208.04.20226.4BookingPress – Appointments Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.13 - SQL Injection CVSS 6.4 · 08.04.202207.12.20226.5BookingPress <= 1.0.30 - Unauthenticated Insecure Direct Object Reference CVSS 6.5 · 07.12.202213.07.20235.3BookingPress <= 1.0.64 - Unauthenticated Sensitive Information Exposure CVSS 5.3 · 13.07.202327.11.20237.2BookingPress <= 1.0.76 - Authenticated (Administrator+) Arbitrary File Upload CVSS 7.2 · 27.11.202321.12.20238.8BookingPress <= 1.0.72 - Authenticated (Contributor+) SQL Injection CVSS 8.8 · 21.12.202327.12.20237.5BookingPress <= 1.0.74 - Booking Price Manipulation via bookingpress_confirm_booking CVSS 7.5 · 27.12.202303.04.20247.2BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.87 - Authenticated (Admin+) Arbitrary File Upload CVSS 7.2 · 03.04.202405.04.20244.3BookingPress <= 1.0.81 - Authenticated (Customer+) Insecure Direct Object Reference CVSS 4.3 · 05.04.202420.05.20245.3BookingPress <= 1.0.82 - Missing Authorization to Appointment Time Alteration CVSS 5.3 · 20.05.202416.07.20248.8BookingPress Appointment Booking <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation CVSS 8.8 · 16.07.20248.8BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload CVSS 8.8 · 16.07.202407.08.20249.8Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover CVSS 9.8 · 07.08.202401.11.20245.3Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection CVSS 5.3 · 01.11.202423.12.20245.3BookingPress <= 1.1.22 - Unauthenticated File Export Download CVSS 5.3 · 23.12.20246.5Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress <= 1.1.21 - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 23.12.202424.01.20256.4BookingPress <= 1.1.25 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 24.01.202501.04.20254.9BookingPress <= 1.1.28 - Authenticated (Administrator+) SQL Injection CVSS 4.9 · 01.04.2025

Strategic Overview

Avg CVSSMedium
6.9/ 10
Patch Coverage100%
Open

0

Fixed

18

Get automatic notifications for all Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress vulnerabilities before they are exploited.

Vulnerability Records

18 records
2025-04-01 00:00CVE-2025-31910
4.9
Medium
Phat RiOYes
2025-01-24 00:00CVE-2025-24732
6.4
Medium
zaimYes
2024-12-23 00:00CVE-2024-12274
5.3
Medium
Thanh HangYes
2024-12-23 00:00CVE-2024-11726
6.5
Medium
shaman0x01Yes
2024-11-01 00:00CVE-2024-10540
5.3
Medium
Arkadiusz HydzikYes
2024-08-07 00:00CVE-2024-7350
9.8
Critical
Gibran AbdillahYes
2024-07-16 18:09CVE-2024-6660
8.8
High
shaman0x01Yes
2024-07-16 00:00CVE-2024-6467
8.8
High
Arkadiusz HydzikYes
2024-05-20 00:00CVE-2024-34799
5.3
Medium
Mochamad SofyanYes
2024-04-05 00:00CVE-2024-31296
4.3
Medium
Steven JulianYes
Showing 1–10 of 18 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C