Planyo online reservation system

Planyo online reservation system has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Improper Input Validation.

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

2 independent researchers contributed these findings, one record each. Planyo online reservation system is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all Planyo online reservation system vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2025-31811

Planyo online reservation system <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv3.1

Planyo online reservation system

xtreeme

Author

xtreeme

0.0(0)
0/100
Last Updated
2026-03-23 (6mo ago)
Active Installs
400+
Downloads
18,595
Requires WP
2.5+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2010-01-08 (17y ago)

Planyo is the most flexible online booking and reservation system which will work for any kind of business such as hotels, holiday apartments, yacht rentals, driving schools, tennis courts, doctor appointments, events etc. Planyo is available in 30+ languages in the frontend and 6 in the backend and helps you manage your clients’ bookings by handling all email communication with the clients, allowing various booking confirmation mechanisms, handling payments (also online credit card payments), printing invoices etc. This module embeds the entire booking system into your site so the visitors can go through the whole process (search, reservation etc) without ever leaving your website. Before using this module you should create an account at planyo.com. Please see http://www.planyo.com/wordpress-reservation-system for more info. You can also see our home page at http://www.planyo.com for admin backoffice or visitor demonstration, or for tutorial movies, pricing and more info. Key features: Accept bookings in 30+ languages, backend in 6 languages Freely designed booking form with extra items of any type Customer never leaves your website Use with over 30 online payment gateways Easy integration with plugins for WordPress, Joomla, Drupal Many integrations such as Mailchimp, Google cal., accounting Support for mobile devices and responsive design Dedicated free iPhone and Android apps for the admins Set up automated notifications by email and SMS Printable invoices and extra documents as PDF attachments Customers can modify or cancel their bookings Customers can add one-time or recurring products Any pricing model can be entered Synchronize with other calendars via iCal or dedicated apps Vouchers, coupons, gift certificates, packages, bundles Support for agents and multiple administrative roles Meta sites for large infrastructures or tourist areas Extensive API for custom extensions Advanced reporting and data analysis Shopping cart for reservation of multiple resources Usage You’ll find the tutorial at http://www.planyo.com/wordpress-reservation-system/. In short: use the [planyo] shortcode wherever you want the planyo reservation system to appear:

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C