Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter
medium
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce verific...
- CVSS:
- 5.3
- Affected:
- up to 2.9.9.6.8
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2026
CVE-2026-12128 on NVD →
Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Injection via 'field' Parameter
medium
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...
- CVSS:
- 4.9
- Affected:
- up to 2.9.9.6.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 31, 2026
CVE-2026-15403 on NVD →
Pinpoint Booking System <= 2.9.9.6.5 - Missing Authorization
medium
The Pinpoint Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.9.9.6.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.9.9.6.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2026-39678 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] <= 2.9.9.5.4 (unfixed)
unknown
[en] The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up to, and including, 2.9.9.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...
- Affected:
- up to 2.9.9.5.4
- Fix:
- No patched version reported
- Disclosed:
- Feb 21, 2025
CVE-2024-13235 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin <= 2.9.9.5.4 - Authenticated (Subscriber+) SQL Injection
medium
The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up to, and including, 2.9.9.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...
- CVSS:
- 6.5
- Affected:
- up to 2.9.9.5.4
- Fixed in:
- 2.9.9.6.0
- Disclosed:
- Feb 20, 2025
CVE-2024-13235 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] <= 2.9.9.5.6 (unfixed)
unknown
[en] Missing Authorization vulnerability in Pinpoint Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.6.
- Affected:
- up to 2.9.9.5.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 13, 2024
CVE-2024-54252 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 2.9.9.5.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Blind SQL Injection.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.1.
- Affected:
- up to 2.9.9.5.2
- Fixed in:
- 2.9.9.5.2
- Disclosed:
- Dec 6, 2024
CVE-2024-53815 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin <= 2.9.9.5.7 - Missing Authorization
medium
The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.9.5.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an u...
- CVSS:
- 6.3
- Affected:
- up to 2.9.9.5.7
- Fixed in:
- 2.9.9.5.8
- Disclosed:
- Dec 5, 2024
CVE-2024-54252 on NVD →
Pinpoint Booking System <= 2.9.9.5.1 - Authenticated (Subscriber+) SQL Injection
medium
The Pinpoint Booking System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level...
- CVSS:
- 6.5
- Affected:
- up to 2.9.9.5.1
- Fixed in:
- 2.9.9.5.2
- Disclosed:
- Dec 2, 2024
CVE-2024-53815 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] <= 2.9.9.5.6 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Stored XSS.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.1.
- Affected:
- up to 2.9.9.5.6
- Fix:
- No patched version reported
- Disclosed:
- Oct 17, 2024
CVE-2024-49304 on NVD →
Pinpoint Booking System <= 2.9.9.5.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Pinpoint Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.9.5.7. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to modify settings and inject malicious web scripts via a for...
- CVSS:
- 6.1
- Affected:
- up to 2.9.9.5.7
- Fixed in:
- 2.9.9.5.8
- Disclosed:
- Oct 15, 2024
CVE-2024-49304 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 2.9.9.5.1
unknown
[en] The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up to, and including, 2.9.9.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...
- Affected:
- up to 2.9.9.5.1
- Fixed in:
- 2.9.9.5.1
- Disclosed:
- Sep 7, 2024
CVE-2024-7112 on NVD →
Pinpoint Booking System <= 2.9.9.5.0- Authenticated (Subscriber+) SQL Injection
high
The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up to, and including, 2.9.9.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...
- CVSS:
- 8.8
- Affected:
- up to 2.9.9.5.0
- Fixed in:
- 2.9.9.5.1
- Disclosed:
- Sep 6, 2024
CVE-2024-7112 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 2.9.9.4.8
unknown
[en] The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.9.9.4.8
- Fixed in:
- 2.9.9.4.8
- Disclosed:
- Aug 5, 2024
CVE-2024-3636 on NVD →
Pinpoint Booking System <= 2.9.9.4.7 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Pinpoint Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.9.9.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...
- CVSS:
- 4.4
- Affected:
- up to 2.9.9.4.7
- Fixed in:
- 2.9.9.4.8
- Disclosed:
- Jul 15, 2024
CVE-2024-3636 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 2.9.9.3.5
unknown
[en] External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.
- Affected:
- up to 2.9.9.3.5
- Fixed in:
- 2.9.9.3.5
- Disclosed:
- Jun 4, 2024
CVE-2023-38520 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 2.9.9.4.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.4.0 versions.
- Affected:
- up to 2.9.9.4.1
- Fixed in:
- 2.9.9.4.1
- Disclosed:
- Oct 13, 2023
CVE-2023-45270 on NVD →
Pinpoint Booking System <= 2.9.9.4.0 - Cross-Site Request Forgery via initBackEndAJAX
medium
The Pinpoint Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.9.4.0. This is due to missing or incorrect nonce validation on the initBackEndAJAX function and the functions it calls. This makes it possible for unauthenticated attackers to create, modif...
- CVSS:
- 5.4
- Affected:
- up to 2.9.9.4.0
- Fixed in:
- 2.9.9.4.1
- Disclosed:
- Oct 6, 2023
CVE-2023-45270 on NVD →
Pinpoint Booking System <= 2.9.9.3.4 - Content Spoofing
medium
The Pinpoint Booking System plugin for WordPress is vulnerable to content spoofing in versions up to, and including, 2.9.9.3.4. This makes it possible for unauthenticated attackers to inject content that may alter the content and display of select pages.
- CVSS:
- 5.3
- Affected:
- up to 2.9.9.3.4
- Fixed in:
- 2.9.9.3.5
- Disclosed:
- Jul 20, 2023
CVE-2023-38520 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 2.9.9.2.9
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.2.8 versions.
- Affected:
- up to 2.9.9.2.9
- Fixed in:
- 2.9.9.2.9
- Disclosed:
- Apr 6, 2023
CVE-2023-25062 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 2.9.9.2.9
unknown
[en] The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.
- Affected:
- up to 2.9.9.2.9
- Fixed in:
- 2.9.9.2.9
- Disclosed:
- Feb 13, 2023
CVE-2023-0220 on NVD →
Pinpoint Booking System <= 2.9.9.2.8 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Pinpoint Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.9.9.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 2.9.9.2.9
- Fixed in:
- 2.9.9.2.9
- Disclosed:
- Feb 2, 2023
CVE-2023-25062 on NVD →
Pinpoint Booking System <= 2.9.9.2.8 - Authenticated (Subscriber+) SQL Injection
high
The Pinpoint Booking System plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 2.9.9.2.8 due to insufficient escaping on the user supplied attributes and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...
- CVSS:
- 8.8
- Affected:
- up to 2.9.9.2.8
- Fixed in:
- 2.9.9.2.9
- Disclosed:
- Jan 23, 2023
CVE-2023-0220 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 2.1
unknown
[en] The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Oct 10, 2019
CVE-2015-9460 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 1.4
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- Nov 24, 2015
Pinpoint Booking System – #1 WordPress Booking Plugin < 2.1 - Authenticated SQL Injection
high
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
- CVSS:
- 8.8
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Jul 7, 2015
CVE-2015-9460 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 2.1
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands via "language" parameter.
Update the plugin.
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Jul 7, 2015
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 1.4
unknown
[en] SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php.
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- May 22, 2014
CVE-2014-3210 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin < 1.3 - SQL Injection
high
SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php.
- CVSS:
- 8.8
- Affected:
- up to 1.3
- Fixed in:
- 1.3
- Disclosed:
- May 21, 2014
CVE-2014-3210 on NVD →
Pinpoint Booking System – #1 WordPress Booking Plugin <= 1.3.1 - Reflected Cross-Site Scripting
medium
The Booking System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eid’ parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- CVSS:
- 6.1
- Affected:
- up to 1.3.1
- Fixed in:
- 1.4
- Disclosed:
- Jul 4, 2013
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 1.4
unknown
The Booking System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eid’ parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- Jul 4, 2013
Pinpoint Booking System – #1 WordPress Booking Plugin [booking-system] < 1.4
unknown
The Pinpoint Booking System – #1 WordPress Booking Plugin WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.4
- Fixed in:
- 1.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database