Bookster – WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injection via 'raw'
medium
The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘raw’ parameter in all versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...
- CVSS:
- 4.9
- Affected:
- up to 2.1.1
- Fixed in:
- 2.2.0
- Disclosed:
- Feb 17, 2026
CVE-2025-8781 on NVD →
Bookster – WordPress Appointment Booking Plugin [bookster] < 1.2.0
unknown
[en] The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Jun 26, 2024
CVE-2024-5071 on NVD →
Bookster – WordPress Appointment Booking Plugin <= 1.1.0 - Unauthenticated Appointment Manipulation
medium
The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to unauthorized data manipulation in all versions up to, and including, 1.1.0. This is due to the plugin not properly validating the book_status parameter. This makes it possible for unauthenticated attackers to update their booking...
- CVSS:
- 5.3
- Affected:
- up to 1.1.0
- Fixed in:
- 1.2.0
- Disclosed:
- Jun 5, 2024
CVE-2024-5071 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database