Booktics 1.0.22 - Authenticated (Subscriber+) SQL Injection
medium
The Booktics plugin for WordPress is vulnerable to SQL Injection in versions up to 1.0.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additi...
- CVSS:
- 6.5
- Affected:
- 1.0.22 – 1.0.22
- Fixed in:
- 1.0.23
- Disclosed:
- Aug 12, 2026
CVE-2026-28002 on NVD →
Booktics <= 1.0.21 - Unauthenticated PHP Object Injection
high
The Booktics plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.21 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an...
- CVSS:
- 8.1
- Affected:
- up to 1.0.21
- Fixed in:
- 1.0.22
- Disclosed:
- Jun 29, 2026
CVE-2026-57621 on NVD →
Booktics - Missing Authorization to Get Items via REST API endpoints vulnerability
medium
Missing Authorization to Get Items via REST API endpoints vulnerability
- CVSS:
- 5.3
- Affected:
- up to 1.0.16
- Fixed in:
- 1.0.17
- Disclosed:
- Mar 10, 2026
Booktics <= 1.0.16 - Missing Authorization to Get Items via REST API endpoints
medium
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to query sensitive...
- CVSS:
- 5.3
- Affected:
- up to 1.0.16
- Fixed in:
- 1.0.17
- Disclosed:
- Mar 9, 2026
CVE-2026-1919 on NVD →
Booktics <= 1.0.16 - Missing Authorization to Addon Plugin Installation
medium
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'Extension_Controller::update_item_permissions_check' function in all versions up to, and including, 1.0.16. This makes it possible for...
- CVSS:
- 5.3
- Affected:
- up to 1.0.16
- Fixed in:
- 1.0.17
- Disclosed:
- Mar 9, 2026
CVE-2026-1920 on NVD →
Booktics <= 1.0.16 - Missing Authorization
medium
The Booktics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.0.16
- Fixed in:
- 1.0.17
- Disclosed:
- Feb 2, 2026
CVE-2026-39585 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database