plugin

Commons Booking Vulnerabilities

4 known security issues reported for the Commons Booking WordPress plugin. Most recent disclosed Jun 21, 2024.

2 medium

Running Commons Booking on your site? Check whether your installed version is affected.

Scan your site free

CB (legacy) [commons-booking] <= 0.9.4.18 (unfixed + closed)

unknown

[en] The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 0.9.4.18
Fix:
No patched version reported
Disclosed:
Jun 21, 2024

CVE-2024-4381 on NVD →

CB (legacy) [commons-booking] <= 0.9.4.18 (unfixed + closed)

unknown

[en] The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks

Affected:
up to 0.9.4.18
Fix:
No patched version reported
Disclosed:
Jun 21, 2024

CVE-2024-4382 on NVD →

CB (legacy) <= 0.9.4.18 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The CB (legacy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.9.4.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject ar...

CVSS:
4.4
Affected:
up to 0.9.4.18
Fix:
No patched version reported
Disclosed:
May 31, 2024

CVE-2024-4381 on NVD →

CB (legacy) <= 0.9.4.18 - Cross-Site Request Forgery to Code/Timeframe/Booking Deletion

medium

The CB (legacy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.4.18. This is due to missing or incorrect nonce validation on a bulk update function. This makes it possible for unauthenticated attackers to delete codes, timeframes and bookings via a forged requ...

CVSS:
4.3
Affected:
up to 0.9.4.18
Fix:
No patched version reported
Disclosed:
May 31, 2024

CVE-2024-4382 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database