Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter
high
The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthent...
- CVSS:
- 7.5
- Affected:
- up to 1.7.20
- Fixed in:
- 1.7.21
- Disclosed:
- Jul 10, 2026
CVE-2026-15335 on NVD →
Booking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action
high
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only validates a nonce and the dispatcher invokes...
- CVSS:
- 7.2
- Affected:
- up to 1.7.16
- Fixed in:
- 1.7.17
- Disclosed:
- Jun 5, 2026
CVE-2026-9851 on NVD →
Booking Package <= 1.7.06 - Unauthenticated Price Manipulation via 'amount' Parameter
medium
The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the commitStripe() function ignoring the server-ca...
- CVSS:
- 5.3
- Affected:
- up to 1.7.06
- Fixed in:
- 1.7.07
- Disclosed:
- Apr 27, 2026
CVE-2026-4911 on NVD →
Booking Package <= 1.7.06 - Missing Authorization
medium
The Booking Package plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.06. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.7.06
- Fixed in:
- 1.7.07
- Disclosed:
- Apr 21, 2026
CVE-2026-40774 on NVD →
Booking Package <= 1.6.72 - Reflected Cross-Site Scripting via Locale Parameter
medium
The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...
- CVSS:
- 6.1
- Affected:
- up to 1.6.72
- Fixed in:
- 1.6.73
- Disclosed:
- Feb 18, 2025
CVE-2024-13508 on NVD →
Booking Package [booking-package] < 1.6.73
unknown
[en] The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- Affected:
- up to 1.6.73
- Fixed in:
- 1.6.73
- Disclosed:
- Feb 18, 2025
CVE-2024-13508 on NVD →
Booking Package [booking-package] < 1.5.99
unknown
[en] Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.
- Affected:
- up to 1.5.99
- Fixed in:
- 1.5.99
- Disclosed:
- May 17, 2024
CVE-2023-37389 on NVD →
Booking Package <= 1.6.27 - Unauthenticated Price Manipulation
medium
The Booking Package plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 1.6.27. This is due to insufficient validation on the pricing data being passed to the server. This makes it possible for unauthenticated attackers to modify the price of bookings.
- CVSS:
- 5.3
- Affected:
- up to 1.6.27
- Fixed in:
- 1.6.29
- Disclosed:
- Mar 28, 2024
CVE-2024-30516 on NVD →
Booking Package [booking-package] < 1.6.02
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SAASPROJECT Booking Package Booking Package plugin <= 1.6.01 versions.
- Affected:
- up to 1.6.02
- Fixed in:
- 1.6.02
- Disclosed:
- Sep 4, 2023
CVE-2023-39918 on NVD →
Booking Package <= 1.6.01 - Reflected Cross-Site Scripting via 'mode'
medium
The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 1.6.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- CVSS:
- 6.1
- Affected:
- up to 1.6.01
- Fixed in:
- 1.6.02
- Disclosed:
- Aug 7, 2023
CVE-2023-39918 on NVD →
Booking Package <= 1.5.98 - Authorization Bypass to Arbitrary Password Reset
critical
The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 due to missing validation in the 'updateUser' function. This allows unauthenticated attackers to reset the email and password of any user on the site if they know the username. Note that only sites tha...
- CVSS:
- 9.8
- Affected:
- up to 1.5.99
- Fixed in:
- 1.5.99
- Disclosed:
- Jul 5, 2023
CVE-2023-37389 on NVD →
Booking Package [booking-package] < 1.5.99
unknown
The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 due to missing validation in the 'updateUser' function. This allows unauthenticated attackers to reset the email and password of any user on the site if they know the username. Note that only sites tha...
- Affected:
- up to 1.5.99
- Fixed in:
- 1.5.99
- Disclosed:
- Jul 5, 2023
Booking Package [booking-package] < 1.5.29
unknown
[en] The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.
- Affected:
- up to 1.5.29
- Fixed in:
- 1.5.29
- Disclosed:
- Apr 4, 2022
CVE-2022-0709 on NVD →
Booking Package <= 1.5.28 - Unauthenticated Sensitive Data Disclosure
high
The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.
- CVSS:
- 7.5
- Affected:
- up to 1.5.29
- Fixed in:
- 1.5.29
- Disclosed:
- Mar 9, 2022
CVE-2022-0709 on NVD →
Booking Package [booking-package] < 1.5.11
unknown
[en] Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unspecified vectors.
- Affected:
- up to 1.5.11
- Fixed in:
- 1.5.11
- Disclosed:
- Nov 24, 2021
CVE-2021-20840 on NVD →
Booking Package <= 1.5.10 - Reflected Cross-Site Scripting
medium
The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 1.5.11
- Fixed in:
- 1.5.11
- Disclosed:
- Nov 10, 2021
CVE-2021-20840 on NVD →
Booking Package [booking-package] < 1.6.29
unknown
- Affected:
- up to 1.6.29
- Fixed in:
- 1.6.29
CVE-2024-30516 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database