Rezgo Online Booking [rezgo] < 4.17.1
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rezgo Rezgo allows PHP Local File Inclusion.This issue affects Rezgo: from n/a through 4.15.
- Affected:
- up to 4.17.1
- Fixed in:
- 4.17.1
- Disclosed:
- Jan 7, 2025
CVE-2024-53800 on NVD →
Rezgo Online Booking <= 4.17 - Unauthenticated Local File Inclusion
high
The Rezgo Online Booking plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.17. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass acc...
- CVSS:
- 8.1
- Affected:
- up to 4.17
- Fixed in:
- 4.17.1
- Disclosed:
- Jan 6, 2025
CVE-2024-53800 on NVD →
Rezgo Online Booking [rezgo] < 4.1.8
unknown
[en] The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct call to the affected file
- Affected:
- up to 4.1.8
- Fixed in:
- 4.1.8
- Disclosed:
- Aug 22, 2022
CVE-2022-1932 on NVD →
Rezgo Online Booking <= 4.1.7 - Reflected Cross-Site-Scripting
medium
The Rezgo Online Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters such as 'wp_slug' in versions up to, and including, 4.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- 4.1.7 – 4.1.7
- Fixed in:
- 4.1.8
- Disclosed:
- Jul 26, 2022
CVE-2022-1932 on NVD →
Rezgo Online Booking [rezgo] < 2.0.0
unknown
[en] Cross-site scripting (XSS) vulnerability in book_ajax.php in the Rezgo plugin 1.4.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the response parameter.
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Jul 2, 2014
CVE-2014-4546 on NVD →
Rezgo Online Booking < 1.8.2 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in templates/default/index_ajax.php in the Rezgo Online Booking plugin before 1.8.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) tags or (2) search_for parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 28, 2014
CVE-2014-4547 on NVD →
Rezgo Online Booking < 1.4.3 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in book_ajax.php in the Rezgo plugin 1.4.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the response parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- May 28, 2014
CVE-2014-4546 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database