plugin

Booking System Vulnerabilities

32 known security issues reported for the Booking System WordPress plugin. Most recent disclosed Aug 14, 2026.

4 high 12 medium

Running Booking System on your site? Check whether your installed version is affected.

Scan your site free

Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter

medium

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce verific...

CVSS:
5.3
Affected:
up to 2.9.9.6.8
Fix:
No patched version reported
Disclosed:
Aug 14, 2026

CVE-2026-12128 on NVD →

Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Injection via 'field' Parameter

medium

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

CVSS:
4.9
Affected:
up to 2.9.9.6.9
Fix:
No patched version reported
Disclosed:
Jul 31, 2026

CVE-2026-15403 on NVD →

Pinpoint Booking System <= 2.9.9.6.5 - Missing Authorization

medium

The Pinpoint Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.9.9.6.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.9.9.6.5
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2026-39678 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] <= 2.9.9.5.4 (unfixed)

unknown

[en] The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up to, and including, 2.9.9.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

Affected:
up to 2.9.9.5.4
Fix:
No patched version reported
Disclosed:
Feb 21, 2025

CVE-2024-13235 on NVD →

Pinpoint Booking System – #1 WordPress Booking Plugin <= 2.9.9.5.4 - Authenticated (Subscriber+) SQL Injection

medium

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up to, and including, 2.9.9.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...

CVSS:
6.5
Affected:
up to 2.9.9.5.4
Fixed in:
2.9.9.6.0
Disclosed:
Feb 20, 2025

CVE-2024-13235 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] <= 2.9.9.5.6 (unfixed)

unknown

[en] Missing Authorization vulnerability in Pinpoint Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.6.

Affected:
up to 2.9.9.5.6
Fix:
No patched version reported
Disclosed:
Dec 13, 2024

CVE-2024-54252 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 2.9.9.5.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Blind SQL Injection.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.1.

Affected:
up to 2.9.9.5.2
Fixed in:
2.9.9.5.2
Disclosed:
Dec 6, 2024

CVE-2024-53815 on NVD →

Pinpoint Booking System – #1 WordPress Booking Plugin <= 2.9.9.5.7 - Missing Authorization

medium

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.9.5.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an u...

CVSS:
6.3
Affected:
up to 2.9.9.5.7
Fixed in:
2.9.9.5.8
Disclosed:
Dec 5, 2024

CVE-2024-54252 on NVD →

Pinpoint Booking System <= 2.9.9.5.1 - Authenticated (Subscriber+) SQL Injection

medium

The Pinpoint Booking System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level...

CVSS:
6.5
Affected:
up to 2.9.9.5.1
Fixed in:
2.9.9.5.2
Disclosed:
Dec 2, 2024

CVE-2024-53815 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] <= 2.9.9.5.6 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Stored XSS.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.1.

Affected:
up to 2.9.9.5.6
Fix:
No patched version reported
Disclosed:
Oct 17, 2024

CVE-2024-49304 on NVD →

Pinpoint Booking System <= 2.9.9.5.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The Pinpoint Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.9.5.7. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to modify settings and inject malicious web scripts via a for...

CVSS:
6.1
Affected:
up to 2.9.9.5.7
Fixed in:
2.9.9.5.8
Disclosed:
Oct 15, 2024

CVE-2024-49304 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 2.9.9.5.1

unknown

[en] The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up to, and including, 2.9.9.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

Affected:
up to 2.9.9.5.1
Fixed in:
2.9.9.5.1
Disclosed:
Sep 7, 2024

CVE-2024-7112 on NVD →

Pinpoint Booking System <= 2.9.9.5.0- Authenticated (Subscriber+) SQL Injection

high

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up to, and including, 2.9.9.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...

CVSS:
8.8
Affected:
up to 2.9.9.5.0
Fixed in:
2.9.9.5.1
Disclosed:
Sep 6, 2024

CVE-2024-7112 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 2.9.9.4.8

unknown

[en] The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.9.9.4.8
Fixed in:
2.9.9.4.8
Disclosed:
Aug 5, 2024

CVE-2024-3636 on NVD →

Pinpoint Booking System <= 2.9.9.4.7 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Pinpoint Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.9.9.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...

CVSS:
4.4
Affected:
up to 2.9.9.4.7
Fixed in:
2.9.9.4.8
Disclosed:
Jul 15, 2024

CVE-2024-3636 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 2.9.9.3.5

unknown

[en] External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.

Affected:
up to 2.9.9.3.5
Fixed in:
2.9.9.3.5
Disclosed:
Jun 4, 2024

CVE-2023-38520 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 2.9.9.4.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.4.0 versions.

Affected:
up to 2.9.9.4.1
Fixed in:
2.9.9.4.1
Disclosed:
Oct 13, 2023

CVE-2023-45270 on NVD →

Pinpoint Booking System <= 2.9.9.4.0 - Cross-Site Request Forgery via initBackEndAJAX

medium

The Pinpoint Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.9.4.0. This is due to missing or incorrect nonce validation on the initBackEndAJAX function and the functions it calls. This makes it possible for unauthenticated attackers to create, modif...

CVSS:
5.4
Affected:
up to 2.9.9.4.0
Fixed in:
2.9.9.4.1
Disclosed:
Oct 6, 2023

CVE-2023-45270 on NVD →

Pinpoint Booking System <= 2.9.9.3.4 - Content Spoofing

medium

The Pinpoint Booking System plugin for WordPress is vulnerable to content spoofing in versions up to, and including, 2.9.9.3.4. This makes it possible for unauthenticated attackers to inject content that may alter the content and display of select pages.

CVSS:
5.3
Affected:
up to 2.9.9.3.4
Fixed in:
2.9.9.3.5
Disclosed:
Jul 20, 2023

CVE-2023-38520 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 2.9.9.2.9

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.2.8 versions.

Affected:
up to 2.9.9.2.9
Fixed in:
2.9.9.2.9
Disclosed:
Apr 6, 2023

CVE-2023-25062 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 2.9.9.2.9

unknown

[en] The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.

Affected:
up to 2.9.9.2.9
Fixed in:
2.9.9.2.9
Disclosed:
Feb 13, 2023

CVE-2023-0220 on NVD →

Pinpoint Booking System <= 2.9.9.2.8 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Pinpoint Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.9.9.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

CVSS:
4.4
Affected:
up to 2.9.9.2.9
Fixed in:
2.9.9.2.9
Disclosed:
Feb 2, 2023

CVE-2023-25062 on NVD →

Pinpoint Booking System <= 2.9.9.2.8 - Authenticated (Subscriber+) SQL Injection

high

The Pinpoint Booking System plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 2.9.9.2.8 due to insufficient escaping on the user supplied attributes and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...

CVSS:
8.8
Affected:
up to 2.9.9.2.8
Fixed in:
2.9.9.2.9
Disclosed:
Jan 23, 2023

CVE-2023-0220 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 2.1

unknown

[en] The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Oct 10, 2019

CVE-2015-9460 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 1.4

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
Nov 24, 2015

Pinpoint Booking System – #1 WordPress Booking Plugin < 2.1 - Authenticated SQL Injection

high

The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.

CVSS:
8.8
Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Jul 7, 2015

CVE-2015-9460 on NVD →

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 2.1

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands via "language" parameter. Update the plugin.

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Jul 7, 2015

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 1.4

unknown

[en] SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php.

Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
May 22, 2014

CVE-2014-3210 on NVD →

Pinpoint Booking System – #1 WordPress Booking Plugin < 1.3 - SQL Injection

high

SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php.

CVSS:
8.8
Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
May 21, 2014

CVE-2014-3210 on NVD →

Pinpoint Booking System – #1 WordPress Booking Plugin <= 1.3.1 - Reflected Cross-Site Scripting

medium

The Booking System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eid’ parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

CVSS:
6.1
Affected:
up to 1.3.1
Fixed in:
1.4
Disclosed:
Jul 4, 2013

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 1.4

unknown

The Booking System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eid’ parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute i...

Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
Jul 4, 2013

Pinpoint Booking System &#8211; #1 WordPress Booking Plugin [booking-system] < 1.4

unknown

The Pinpoint Booking System &ndash; #1 WordPress Booking Plugin WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.4
Fixed in:
1.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database