plugin

Booking Ultra Pro Vulnerabilities

31 known security issues reported for the Booking Ultra Pro WordPress plugin. Most recent disclosed Jan 22, 2026.

1 critical 7 high 8 medium

Running Booking Ultra Pro on your site? Check whether your installed version is affected.

Scan your site free

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] <= 1.1.23 (unfixed)

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Retrieve Embedded Sensitive Data.This issue affects Booking Ultra Pro: from n/a through <= 1.1.23.

Affected:
up to 1.1.23
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-68006 on NVD →

Booking Ultra Pro <= 1.1.23 - Authenticated (Subscriber+) Information Exposure

medium

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.23. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 1.1.23
Fix:
No patched version reported
Disclosed:
Dec 26, 2025

CVE-2025-68006 on NVD →

Booking Ultra Pro <= 1.1.21 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...

CVSS:
6.4
Affected:
up to 1.1.21
Fixed in:
1.1.22
Disclosed:
Sep 3, 2025

CVE-2025-58633 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.22 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Stored XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.21.

Affected:
up to 1.1.22
Fixed in:
1.1.22
Disclosed:
Sep 3, 2025

CVE-2025-58633 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.21 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Stored XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.20.

Affected:
up to 1.1.21
Fixed in:
1.1.21
Disclosed:
Jun 6, 2025

CVE-2025-30637 on NVD →

Booking Ultra Pro <= 1.1.20 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in p...

CVSS:
4.4
Affected:
up to 1.1.20
Fixed in:
1.1.21
Disclosed:
Jun 5, 2025

CVE-2025-30637 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.20 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Reflected XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.19.

Affected:
up to 1.1.20
Fixed in:
1.1.20
Disclosed:
Apr 17, 2025

CVE-2025-27345 on NVD →

Booking Ultra Pro <= 1.1.19 - Reflected Cross-Site Scripting

medium

The Booking Ultra Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...

CVSS:
6.1
Affected:
up to 1.1.19
Fixed in:
1.1.20
Disclosed:
Feb 21, 2025

CVE-2025-27345 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.7 (closed)

unknown

[en] Missing Authorization vulnerability in Booking Ultra Pro Booking Ultra Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Ultra Pro: from n/a through 1.1.12.

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Dec 13, 2024

CVE-2023-32601 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.14 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Booking Ultra Pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through 1.1.13.

Affected:
up to 1.1.14
Fixed in:
1.1.14
Disclosed:
Jul 20, 2024

CVE-2024-38676 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.14 (closed)

unknown

[en] The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions in all versions up to, and including, 1.1.13. This makes it possible for authenticated attackers, with Subscriber-level acce...

Affected:
up to 1.1.14
Fixed in:
1.1.14
Disclosed:
Jul 18, 2024

CVE-2024-6175 on NVD →

Booking Ultra Pro <= 1.1.13 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Updates

medium

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions called via AJAX like save_fields_settings, bup_delete_user_avatar, bup_crop_avatar_user_profile_image, and more in all versions...

CVSS:
5.4
Affected:
up to 1.1.13
Fixed in:
1.1.14
Disclosed:
Jul 17, 2024

CVE-2024-6175 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.14 (closed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows PHP Local File Inclusion.This issue affects Booking Ultra Pro: from n/a through 1.1.13.

Affected:
up to 1.1.14
Fixed in:
1.1.14
Disclosed:
Jul 12, 2024

CVE-2024-38717 on NVD →

Booking Ultra Pro <= 1.1.13 - Unauthenticated Local File Inclusion

critical

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.13. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those f...

CVSS:
9.8
Affected:
up to 1.1.13
Fixed in:
1.1.14
Disclosed:
Jul 11, 2024

CVE-2024-38717 on NVD →

Booking Ultra Pro <= 1.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...

CVSS:
6.4
Affected:
up to 1.1.13
Fixed in:
1.1.14
Disclosed:
Jul 10, 2024

CVE-2024-38676 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.13 (closed)

unknown

[en] Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.

Affected:
up to 1.1.13
Fixed in:
1.1.13
Disclosed:
May 17, 2024

CVE-2024-32960 on NVD →

Booking Ultra Pro <= 1.1.12 - Authenticated (Contributor+) Privilege Escalation

high

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor-level access and above, to escalate their privileges.

CVSS:
8.8
Affected:
up to 1.1.12
Fixed in:
1.1.13
Disclosed:
Apr 23, 2024

CVE-2024-32960 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.9 (closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.8 versions.

Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Aug 24, 2023

CVE-2023-32511 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.9 (closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8 versions.

Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
Aug 23, 2023

CVE-2023-32236 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.7 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions.

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
May 24, 2023

CVE-2022-46816 on NVD →

Booking Ultra Pro <= 1.1.6 - Missing Authorization via save_fields_settings

medium

The Booking Ultra Pro plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the save_fields_settings function in versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the plugin...

CVSS:
4.3
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
May 12, 2023

CVE-2023-32601 on NVD →

Booking Ultra Pro <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting

high

The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acce...

CVSS:
7.2
Affected:
up to 1.1.8
Fixed in:
1.1.9
Disclosed:
May 10, 2023

CVE-2023-32236 on NVD →

Booking Ultra Pro <= 1.1.8 - Reflected Cross-Site Scripting

high

The Booking Ultra Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will e...

CVSS:
7.2
Affected:
up to 1.1.8
Fixed in:
1.1.9
Disclosed:
May 10, 2023

CVE-2023-32511 on NVD →

Booking Ultra Pro <= 1.1.6 - Cross-Site Request Forgery

high

The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they can...

CVSS:
8.8
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Feb 21, 2023

CVE-2022-46816 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.7 (closed)

unknown

[en] Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress.

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Sep 30, 2022

CVE-2021-36855 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.7 (closed)

unknown

[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress.

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Sep 30, 2022

CVE-2021-36854 on NVD →

Booking Ultra Pro <= 1.1.6 - Cross-Site Request Forgery

high

The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on most AJAX actions. This makes it possible for unauthenticated attackers to inject malicious JavaScript, obtain information about staff u...

CVSS:
8.8
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Sep 29, 2022

CVE-2021-36855 on NVD →

Booking Ultra Pro <= 1.1.6 - Cross-Site Request Forgery

high

The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on most AJAX actions. This makes it possible for unauthenticated attackers to inject malicious JavaScript, obtain information about staff u...

CVSS:
8.8
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Sep 29, 2022

CVE-2021-36854 on NVD →

Booking Ultra Pro <= 1.1.5 - Missing Authorization

high

The Booking Ultra Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on most AJAX actions in versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update user profiles, change opening hours...

CVSS:
8.8
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Sep 29, 2022

Booking Ultra Pro <= 1.1.8 - Stored Cross-Site Scripting

medium

The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject ar...

CVSS:
6.4
Affected:
up to 1.1.8
Fixed in:
1.1.9
Disclosed:
Sep 29, 2022

CVE-2021-36854 on NVD →

Booking Ultra Pro Appointments Booking Calendar Plugin [booking-ultra-pro] < 1.1.6 (closed)

unknown

The Booking Ultra Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on most AJAX actions in versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update user profiles, change opening hours...

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Sep 29, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database