plugin

Bookster Vulnerabilities

3 known security issues reported for the Bookster WordPress plugin. Most recent disclosed Feb 17, 2026.

2 medium

Running Bookster on your site? Check whether your installed version is affected.

Scan your site free

Bookster – WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injection via 'raw'

medium

The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘raw’ parameter in all versions up to, and including, 2.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo...

CVSS:
4.9
Affected:
up to 2.1.1
Fixed in:
2.2.0
Disclosed:
Feb 17, 2026

CVE-2025-8781 on NVD →

Bookster &#8211; WordPress Appointment Booking Plugin [bookster] < 1.2.0

unknown

[en] The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Jun 26, 2024

CVE-2024-5071 on NVD →

Bookster – WordPress Appointment Booking Plugin <= 1.1.0 - Unauthenticated Appointment Manipulation

medium

The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to unauthorized data manipulation in all versions up to, and including, 1.1.0. This is due to the plugin not properly validating the book_status parameter. This makes it possible for unauthenticated attackers to update their booking...

CVSS:
5.3
Affected:
up to 1.1.0
Fixed in:
1.2.0
Disclosed:
Jun 5, 2024

CVE-2024-5071 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database