BookingPress Appointment Booking Pro <= 6.0.6 - Unauthenticated SQL Injection
high
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.0.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers...
- CVSS:
- 7.5
- Affected:
- up to 6.0.6
- Fixed in:
- 6.1
- Disclosed:
- Aug 20, 2026
CVE-2026-68566 on NVD →
BookingPress Pro <= 5.7.2 - Missing Authorization Unauthenticated Information Exposure
medium
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.7.2. This makes it possible for unauthenticated attackers to extract customer data and tamper with bookings.
- CVSS:
- 6.5
- Affected:
- up to 5.7.2
- Fixed in:
- 5.7.3
- Disclosed:
- Jul 6, 2026
CVE-2026-9830 on NVD →
BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter
high
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is inte...
- CVSS:
- 7.5
- Affected:
- up to 5.7.1
- Fixed in:
- 5.7.2
- Disclosed:
- Jun 30, 2026
CVE-2026-11823 on NVD →
BookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field
critical
The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affec...
- CVSS:
- 9.8
- Affected:
- up to 5.6
- Fixed in:
- 5.7
- Disclosed:
- May 21, 2026
CVE-2026-6960 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database