Skip to main content

Vendor/product archive

wpbookingcalendar / wp_booking_calendar CVEs

Beta · best-effort

6 CVEs tagged to wpbookingcalendar / wp_booking_calendar0 Critical, 0 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-4669

Published May 17, 2025

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insu…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13323

Published Jan 14, 2025

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10893

Published Dec 3, 2024

The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cr…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10027

Published Nov 7, 2024

The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform S…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9306

Published Oct 4, 2024

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input s…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8274

Published Aug 30, 2024

The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1