Booking Calendar and Notification <= 4.0.3 - Authentication Bypass
critical
The Booking Calendar and Notification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying a user's identity prior to logging them in. This makes it possible for unauthenticated attackers to log in as other users which...
- CVSS:
- 9.8
- Affected:
- up to 4.0.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 3, 2025
CVE-2025-31381 on NVD →
Booking Calendar and Notification <= 4.0.3 - Unauthenticated SQL Injection
high
The Booking Calendar and Notification plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addi...
- CVSS:
- 7.5
- Affected:
- up to 4.0.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 3, 2025
CVE-2025-31403 on NVD →
Booking Calendar and Notification <= 4.0.3 - Missing Authorization via wpcb_all_bookings, wpcb_update_booking_post, and wpcb_delete_posts Functions
medium
The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on the wpcb_all_bookings(), wpcb_update_booking_post(), and wpcb_delete_posts() functions in all versions up to, and including, 4.0.3. This makes it possible f...
- CVSS:
- 6.5
- Affected:
- up to 4.0.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 28, 2025
CVE-2024-13746 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database