Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] <= 1.1.23 (unfixed)
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Retrieve Embedded Sensitive Data.This issue affects Booking Ultra Pro: from n/a through <= 1.1.23.
- Affected:
- up to 1.1.23
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-68006 on NVD →
Booking Ultra Pro <= 1.1.23 - Authenticated (Subscriber+) Information Exposure
medium
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.23. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 1.1.23
- Fix:
- No patched version reported
- Disclosed:
- Dec 26, 2025
CVE-2025-68006 on NVD →
Booking Ultra Pro <= 1.1.21 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...
- CVSS:
- 6.4
- Affected:
- up to 1.1.21
- Fixed in:
- 1.1.22
- Disclosed:
- Sep 3, 2025
CVE-2025-58633 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.22 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Stored XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.21.
- Affected:
- up to 1.1.22
- Fixed in:
- 1.1.22
- Disclosed:
- Sep 3, 2025
CVE-2025-58633 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.21 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Stored XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.20.
- Affected:
- up to 1.1.21
- Fixed in:
- 1.1.21
- Disclosed:
- Jun 6, 2025
CVE-2025-30637 on NVD →
Booking Ultra Pro <= 1.1.20 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in p...
- CVSS:
- 4.4
- Affected:
- up to 1.1.20
- Fixed in:
- 1.1.21
- Disclosed:
- Jun 5, 2025
CVE-2025-30637 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.20 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Reflected XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.19.
- Affected:
- up to 1.1.20
- Fixed in:
- 1.1.20
- Disclosed:
- Apr 17, 2025
CVE-2025-27345 on NVD →
Booking Ultra Pro <= 1.1.19 - Reflected Cross-Site Scripting
medium
The Booking Ultra Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...
- CVSS:
- 6.1
- Affected:
- up to 1.1.19
- Fixed in:
- 1.1.20
- Disclosed:
- Feb 21, 2025
CVE-2025-27345 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.7 (closed)
unknown
[en] Missing Authorization vulnerability in Booking Ultra Pro Booking Ultra Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Ultra Pro: from n/a through 1.1.12.
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Dec 13, 2024
CVE-2023-32601 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.14 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Booking Ultra Pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through 1.1.13.
- Affected:
- up to 1.1.14
- Fixed in:
- 1.1.14
- Disclosed:
- Jul 20, 2024
CVE-2024-38676 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.14 (closed)
unknown
[en] The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions in all versions up to, and including, 1.1.13. This makes it possible for authenticated attackers, with Subscriber-level acce...
- Affected:
- up to 1.1.14
- Fixed in:
- 1.1.14
- Disclosed:
- Jul 18, 2024
CVE-2024-6175 on NVD →
Booking Ultra Pro <= 1.1.13 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Updates
medium
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions called via AJAX like save_fields_settings, bup_delete_user_avatar, bup_crop_avatar_user_profile_image, and more in all versions...
- CVSS:
- 5.4
- Affected:
- up to 1.1.13
- Fixed in:
- 1.1.14
- Disclosed:
- Jul 17, 2024
CVE-2024-6175 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.14 (closed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows PHP Local File Inclusion.This issue affects Booking Ultra Pro: from n/a through 1.1.13.
- Affected:
- up to 1.1.14
- Fixed in:
- 1.1.14
- Disclosed:
- Jul 12, 2024
CVE-2024-38717 on NVD →
Booking Ultra Pro <= 1.1.13 - Unauthenticated Local File Inclusion
critical
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.13. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those f...
- CVSS:
- 9.8
- Affected:
- up to 1.1.13
- Fixed in:
- 1.1.14
- Disclosed:
- Jul 11, 2024
CVE-2024-38717 on NVD →
Booking Ultra Pro <= 1.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...
- CVSS:
- 6.4
- Affected:
- up to 1.1.13
- Fixed in:
- 1.1.14
- Disclosed:
- Jul 10, 2024
CVE-2024-38676 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.13 (closed)
unknown
[en] Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.
- Affected:
- up to 1.1.13
- Fixed in:
- 1.1.13
- Disclosed:
- May 17, 2024
CVE-2024-32960 on NVD →
Booking Ultra Pro <= 1.1.12 - Authenticated (Contributor+) Privilege Escalation
high
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor-level access and above, to escalate their privileges.
- CVSS:
- 8.8
- Affected:
- up to 1.1.12
- Fixed in:
- 1.1.13
- Disclosed:
- Apr 23, 2024
CVE-2024-32960 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.9 (closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.8 versions.
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
- Disclosed:
- Aug 24, 2023
CVE-2023-32511 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.9 (closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8 versions.
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
- Disclosed:
- Aug 23, 2023
CVE-2023-32236 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.7 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions.
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- May 24, 2023
CVE-2022-46816 on NVD →
Booking Ultra Pro <= 1.1.6 - Missing Authorization via save_fields_settings
medium
The Booking Ultra Pro plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the save_fields_settings function in versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the plugin...
- CVSS:
- 4.3
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- May 12, 2023
CVE-2023-32601 on NVD →
Booking Ultra Pro <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting
high
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acce...
- CVSS:
- 7.2
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.9
- Disclosed:
- May 10, 2023
CVE-2023-32236 on NVD →
Booking Ultra Pro <= 1.1.8 - Reflected Cross-Site Scripting
high
The Booking Ultra Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will e...
- CVSS:
- 7.2
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.9
- Disclosed:
- May 10, 2023
CVE-2023-32511 on NVD →
Booking Ultra Pro <= 1.1.6 - Cross-Site Request Forgery
high
The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they can...
- CVSS:
- 8.8
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Feb 21, 2023
CVE-2022-46816 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.7 (closed)
unknown
[en] Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Sep 30, 2022
CVE-2021-36855 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.7 (closed)
unknown
[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Sep 30, 2022
CVE-2021-36854 on NVD →
Booking Ultra Pro <= 1.1.6 - Cross-Site Request Forgery
high
The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on most AJAX actions. This makes it possible for unauthenticated attackers to inject malicious JavaScript, obtain information about staff u...
- CVSS:
- 8.8
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Sep 29, 2022
CVE-2021-36855 on NVD →
Booking Ultra Pro <= 1.1.6 - Cross-Site Request Forgery
high
The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on most AJAX actions. This makes it possible for unauthenticated attackers to inject malicious JavaScript, obtain information about staff u...
- CVSS:
- 8.8
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Sep 29, 2022
CVE-2021-36854 on NVD →
Booking Ultra Pro <= 1.1.5 - Missing Authorization
high
The Booking Ultra Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on most AJAX actions in versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update user profiles, change opening hours...
- CVSS:
- 8.8
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Sep 29, 2022
Booking Ultra Pro <= 1.1.8 - Stored Cross-Site Scripting
medium
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject ar...
- CVSS:
- 6.4
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.9
- Disclosed:
- Sep 29, 2022
CVE-2021-36854 on NVD →
Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.6 (closed)
unknown
The Booking Ultra Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on most AJAX actions in versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update user profiles, change opening hours...
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Sep 29, 2022