plugin

Rezgo Vulnerabilities

7 known security issues reported for the Rezgo WordPress plugin. Most recent disclosed Jan 7, 2025.

1 high 3 medium

Running Rezgo on your site? Check whether your installed version is affected.

Scan your site free

Rezgo Online Booking [rezgo] < 4.17.1

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rezgo Rezgo allows PHP Local File Inclusion.This issue affects Rezgo: from n/a through 4.15.

Affected:
up to 4.17.1
Fixed in:
4.17.1
Disclosed:
Jan 7, 2025

CVE-2024-53800 on NVD →

Rezgo Online Booking <= 4.17 - Unauthenticated Local File Inclusion

high

The Rezgo Online Booking plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.17. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass acc...

CVSS:
8.1
Affected:
up to 4.17
Fixed in:
4.17.1
Disclosed:
Jan 6, 2025

CVE-2024-53800 on NVD →

Rezgo Online Booking [rezgo] < 4.1.8

unknown

[en] The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting, which can be exploited either via a LFI in an AJAX action, or direct call to the affected file

Affected:
up to 4.1.8
Fixed in:
4.1.8
Disclosed:
Aug 22, 2022

CVE-2022-1932 on NVD →

Rezgo Online Booking <= 4.1.7 - Reflected Cross-Site-Scripting

medium

The Rezgo Online Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters such as 'wp_slug' in versions up to, and including, 4.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
4.1.7 – 4.1.7
Fixed in:
4.1.8
Disclosed:
Jul 26, 2022

CVE-2022-1932 on NVD →

Rezgo Online Booking [rezgo] < 2.0.0

unknown

[en] Cross-site scripting (XSS) vulnerability in book_ajax.php in the Rezgo plugin 1.4.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the response parameter.

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Jul 2, 2014

CVE-2014-4546 on NVD →

Rezgo Online Booking < 1.8.2 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in templates/default/index_ajax.php in the Rezgo Online Booking plugin before 1.8.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) tags or (2) search_for parameter.

CVSS:
6.1
Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 28, 2014

CVE-2014-4547 on NVD →

Rezgo Online Booking < 1.4.3 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in book_ajax.php in the Rezgo plugin 1.4.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the response parameter.

CVSS:
6.1
Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
May 28, 2014

CVE-2014-4546 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database