plugin

Bookingpress Appointment Booking Pro Vulnerabilities

4 known security issues reported for the Bookingpress Appointment Booking Pro WordPress plugin. Most recent disclosed Aug 20, 2026.

1 critical 2 high 1 medium

Running Bookingpress Appointment Booking Pro on your site? Check whether your installed version is affected.

Scan your site free

BookingPress Appointment Booking Pro <= 6.0.6 - Unauthenticated SQL Injection

high

The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.0.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers...

CVSS:
7.5
Affected:
up to 6.0.6
Fixed in:
6.1
Disclosed:
Aug 20, 2026

CVE-2026-68566 on NVD →

BookingPress Pro <= 5.7.2 - Missing Authorization Unauthenticated Information Exposure

medium

The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.7.2. This makes it possible for unauthenticated attackers to extract customer data and tamper with bookings.

CVSS:
6.5
Affected:
up to 5.7.2
Fixed in:
5.7.3
Disclosed:
Jul 6, 2026

CVE-2026-9830 on NVD →

BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter

high

The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is inte...

CVSS:
7.5
Affected:
up to 5.7.1
Fixed in:
5.7.2
Disclosed:
Jun 30, 2026

CVE-2026-11823 on NVD →

BookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field

critical

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affec...

CVSS:
9.8
Affected:
up to 5.6
Fixed in:
5.7
Disclosed:
May 21, 2026

CVE-2026-6960 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database