Reservation.Studio widget
Reservation.Studio widget has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for Reservation.Studio widget has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Reservation.Studio widget is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2023-24397Reservation.Studio widget <= 1.0.11 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Reservation.Studio widget
Author
veneliniliev
Reservation.Studio is an online booking platform for service-based businesses. The plugin adds a booking widget to your WordPress site and connects your website with your Reservation.Studio / Reservation.Business profile. Main capabilities: – Enable or disable widget loading from WordPress admin. – Configure booking page type and slug. – Choose language (Auto detect, English, Bulgarian). – Configure sticky button text, colors, position and tooltip behavior. – Configure modal max width and max height. – Optionally bind widget opening to custom CSS selectors. – Embed booking triggers with shortcodes [reservation_studio_button] and [reservation_studio_anchor]. – Render booking directly inline with [reservation_studio_embed] (iframe, no modal). The admin settings screen validates input and shows field-specific error messages directly on the relevant fields. Sign up for free Sign up for a free Reservation.Business account at reservation.business, no credit card required. The Free version includes unlimited appointments, clients, employees, locations and the Desktop, iOS and Android app. Please click here for more information on Pricing.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C