plugin

Smart Appointment Booking Vulnerabilities

2 known security issues reported for the Smart Appointment Booking WordPress plugin. Most recent disclosed May 11, 2026.

2 medium

Running Smart Appointment Booking on your site? Check whether your installed version is affected.

Scan your site free

Smart Appointment & Booking <= 1.0.8 - Missing Authorization to Unauthenticated Arbitrary Booking Cancellation

medium

The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and including, 1.0.8. The nonce check uses && (AND) instead of || (OR), which means pro...

CVSS:
5.3
Affected:
up to 1.0.8
Fixed in:
2.0.0
Disclosed:
May 11, 2026

CVE-2026-5693 on NVD →

Smart Appointment & Booking <= 1.0.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via saab_save_form_data AJAX Action

medium

The Smart Appointment & Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saab_save_form_data AJAX action in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
Feb 3, 2026

CVE-2026-0742 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database