plugin

Booking Package Vulnerabilities

17 known security issues reported for the Booking Package WordPress plugin. Most recent disclosed Jul 10, 2026.

1 critical 3 high 6 medium

Running Booking Package on your site? Check whether your installed version is affected.

Scan your site free

Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter

high

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthent...

CVSS:
7.5
Affected:
up to 1.7.20
Fixed in:
1.7.21
Disclosed:
Jul 10, 2026

CVE-2026-15335 on NVD →

Booking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action

high

The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only validates a nonce and the dispatcher invokes...

CVSS:
7.2
Affected:
up to 1.7.16
Fixed in:
1.7.17
Disclosed:
Jun 5, 2026

CVE-2026-9851 on NVD →

Booking Package <= 1.7.06 - Unauthenticated Price Manipulation via 'amount' Parameter

medium

The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the commitStripe() function ignoring the server-ca...

CVSS:
5.3
Affected:
up to 1.7.06
Fixed in:
1.7.07
Disclosed:
Apr 27, 2026

CVE-2026-4911 on NVD →

Booking Package <= 1.7.06 - Missing Authorization

medium

The Booking Package plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.06. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.7.06
Fixed in:
1.7.07
Disclosed:
Apr 21, 2026

CVE-2026-40774 on NVD →

Booking Package <= 1.6.72 - Reflected Cross-Site Scripting via Locale Parameter

medium

The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...

CVSS:
6.1
Affected:
up to 1.6.72
Fixed in:
1.6.73
Disclosed:
Feb 18, 2025

CVE-2024-13508 on NVD →

Booking Package [booking-package] < 1.6.73

unknown

[en] The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 1.6.73
Fixed in:
1.6.73
Disclosed:
Feb 18, 2025

CVE-2024-13508 on NVD →

Booking Package [booking-package] < 1.5.99

unknown

[en] Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.

Affected:
up to 1.5.99
Fixed in:
1.5.99
Disclosed:
May 17, 2024

CVE-2023-37389 on NVD →

Booking Package <= 1.6.27 - Unauthenticated Price Manipulation

medium

The Booking Package plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 1.6.27. This is due to insufficient validation on the pricing data being passed to the server. This makes it possible for unauthenticated attackers to modify the price of bookings.

CVSS:
5.3
Affected:
up to 1.6.27
Fixed in:
1.6.29
Disclosed:
Mar 28, 2024

CVE-2024-30516 on NVD →

Booking Package [booking-package] < 1.6.02

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SAASPROJECT Booking Package Booking Package plugin <= 1.6.01 versions.

Affected:
up to 1.6.02
Fixed in:
1.6.02
Disclosed:
Sep 4, 2023

CVE-2023-39918 on NVD →

Booking Package <= 1.6.01 - Reflected Cross-Site Scripting via 'mode'

medium

The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 1.6.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

CVSS:
6.1
Affected:
up to 1.6.01
Fixed in:
1.6.02
Disclosed:
Aug 7, 2023

CVE-2023-39918 on NVD →

Booking Package <= 1.5.98 - Authorization Bypass to Arbitrary Password Reset

critical

The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 due to missing validation in the 'updateUser' function. This allows unauthenticated attackers to reset the email and password of any user on the site if they know the username. Note that only sites tha...

CVSS:
9.8
Affected:
up to 1.5.99
Fixed in:
1.5.99
Disclosed:
Jul 5, 2023

CVE-2023-37389 on NVD →

Booking Package [booking-package] < 1.5.99

unknown

The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 due to missing validation in the 'updateUser' function. This allows unauthenticated attackers to reset the email and password of any user on the site if they know the username. Note that only sites tha...

Affected:
up to 1.5.99
Fixed in:
1.5.99
Disclosed:
Jul 5, 2023

Booking Package [booking-package] < 1.5.29

unknown

[en] The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

Affected:
up to 1.5.29
Fixed in:
1.5.29
Disclosed:
Apr 4, 2022

CVE-2022-0709 on NVD →

Booking Package <= 1.5.28 - Unauthenticated Sensitive Data Disclosure

high

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

CVSS:
7.5
Affected:
up to 1.5.29
Fixed in:
1.5.29
Disclosed:
Mar 9, 2022

CVE-2022-0709 on NVD →

Booking Package [booking-package] < 1.5.11

unknown

[en] Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unspecified vectors.

Affected:
up to 1.5.11
Fixed in:
1.5.11
Disclosed:
Nov 24, 2021

CVE-2021-20840 on NVD →

Booking Package <= 1.5.10 - Reflected Cross-Site Scripting

medium

The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...

CVSS:
6.1
Affected:
up to 1.5.11
Fixed in:
1.5.11
Disclosed:
Nov 10, 2021

CVE-2021-20840 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database