RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1223 - Missing Authorization
medium
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1223. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.1223
- Fixed in:
- 4.1224
- Disclosed:
- Aug 24, 2026
CVE-2026-78291 on NVD →
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1121 - Missing Authorization
medium
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1121. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an u...
- CVSS:
- 4.3
- Affected:
- up to 4.1121
- Fixed in:
- 4.1125
- Disclosed:
- May 26, 2026
CVE-2026-24638 on NVD →
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1132 - Missing Authorization
medium
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1132. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an u...
- CVSS:
- 4.3
- Affected:
- up to 4.1132
- Fixed in:
- 4.1133
- Disclosed:
- Apr 20, 2026
CVE-2026-39584 on NVD →
RepairBuddy <= 4.1132 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via wc_rep_shop_settings_submission AJAX Action
medium
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to modify admin-level plugin settings. First, the wc_rb_get_fresh_nonce() function (r...
- CVSS:
- 5.3
- Affected:
- up to 4.1132
- Fixed in:
- 4.1133
- Disclosed:
- Mar 20, 2026
CVE-2026-3567 on NVD →
RepairBuddy <= 4.1132 - Unauthenticated Information Exposure
medium
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1132. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.1132
- Fixed in:
- 4.1133
- Disclosed:
- Feb 26, 2026
CVE-2026-39586 on NVD →
RepairBuddy <= 4.1116 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders
medium
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This makes it possible for authenticated attackers,...
- CVSS:
- 4.3
- Affected:
- up to 4.1116
- Fixed in:
- 4.1121
- Disclosed:
- Jan 16, 2026
CVE-2026-0820 on NVD →
CRM WordPress Plugin – RepairBuddy <= 3.8213 - Missing Authorization
medium
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8213. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.8213
- Fixed in:
- 3.8214
- Disclosed:
- Apr 4, 2025
CVE-2025-32277 on NVD →
CRM WordPress Plugin – RepairBuddy [computer-repair-shop] <= 3.8213 (unfixed)
unknown
[en] Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.
- Affected:
- up to 3.8213
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32277 on NVD →
CRM WordPress Plugin – RepairBuddy [computer-repair-shop] < 3.8120
unknown
[en] Missing Authorization vulnerability in Webful Creations Computer Repair Shop allows Privilege Escalation.This issue affects Computer Repair Shop: from n/a through 3.8119.
- Affected:
- up to 3.8120
- Fixed in:
- 3.8120
- Disclosed:
- Dec 31, 2024
CVE-2024-56061 on NVD →
Computer Repair Shop <= 3.8119 - Authenticated (Customer+) Privilege Esclation via Account Takeover
critical
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to account takeover in all versions up to, and including, 3.8119. This makes it possible for authenticated attackers, with Customer-level access and above, to gain access to other users accounts which may have higher privileges.
- CVSS:
- 9.8
- Affected:
- up to 3.8119
- Fixed in:
- 3.8120
- Disclosed:
- Dec 18, 2024
CVE-2024-56061 on NVD →
CRM WordPress Plugin – RepairBuddy [computer-repair-shop] < 3.8122
unknown
[en] The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the wc_update_user_data AJAX action. This ma...
- Affected:
- up to 3.8122
- Fixed in:
- 3.8122
- Disclosed:
- Dec 18, 2024
CVE-2024-12259 on NVD →
CRM WordPress Plugin – RepairBuddy <= 3.8120 - Missing Authorization to Account Takeover/Privilege Escalation
high
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the wc_update_user_data AJAX action. This makes i...
- CVSS:
- 8.8
- Affected:
- up to 3.8120
- Fixed in:
- 3.8122
- Disclosed:
- Dec 17, 2024
CVE-2024-12259 on NVD →
CRM WordPress Plugin – RepairBuddy [computer-repair-shop] < 3.8116
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Webful Creations Computer Repair Shop allows Upload a Web Shell to a Web Server.This issue affects Computer Repair Shop: from n/a through 3.8115.
- Affected:
- up to 3.8116
- Fixed in:
- 3.8116
- Disclosed:
- Nov 11, 2024
CVE-2024-51793 on NVD →
Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload
critical
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.8115. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code ex...
- CVSS:
- 9.8
- Affected:
- up to 3.8115
- Fixed in:
- 3.8116
- Disclosed:
- Nov 8, 2024
CVE-2024-51793 on NVD →
CRM WordPress Plugin – RepairBuddy <= 3.72 - SQL Injection
high
The plugin CRM WordPress Plugin for WordPress is vulnerable to SQL injection via several parameters in versions up to, and including, 3.72 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation of the SQL query. This makes it possible for an attacker to append additional SQL quer...
- CVSS:
- 8.8
- Affected:
- up to 3.72
- Fixed in:
- 3.73
- Disclosed:
- May 19, 2022
CRM WordPress Plugin – RepairBuddy [computer-repair-shop] < 3.73
unknown
The plugin CRM WordPress Plugin for WordPress is vulnerable to SQL injection via several parameters in versions up to, and including, 3.72 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation of the SQL query. This makes it possible for an attacker to append additional SQL quer...
- Affected:
- up to 3.73
- Fixed in:
- 3.73
- Disclosed:
- May 19, 2022
Computer Repair Shop < 2.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Computer Repair Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privileges to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.6
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Jan 13, 2020
CRM WordPress Plugin – RepairBuddy [computer-repair-shop] < 2.0
unknown
Cross-Site Scripting (XSS) vulnerability discovered by Jeroen Mulder in WordPress Computer Repair Shop plugin (versions <= 1.0).
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Jan 13, 2020
CRM WordPress Plugin – RepairBuddy [computer-repair-shop] < 2.0
unknown
The Computer Repair Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privileges to inject arbitrary web scripts in pages tha...
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Jan 13, 2020
CRM WordPress Plugin – RepairBuddy [computer-repair-shop] < 2.0
unknown
Computer Repair Shop is vulnerable to stored XSS. When a user has admin capabilities, malicious code can be submitted through the plugin's options. Fixed in version 2.0.
- Affected:
- up to 2.0
- Fixed in:
- 2.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database