plugin

Wedesigntech Ultimate Booking Addon Vulnerabilities

8 known security issues reported for the Wedesigntech Ultimate Booking Addon WordPress plugin. Most recent disclosed Mar 5, 2026.

1 critical 1 high 2 medium

Running Wedesigntech Ultimate Booking Addon on your site? Check whether your installed version is affected.

Scan your site free

WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon] <= 1.0.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3.

Affected:
up to 1.0.3
Fix:
No patched version reported
Disclosed:
Mar 5, 2026

CVE-2025-69340 on NVD →

WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon] <= 1.0.1 (unfixed)

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1.

Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Mar 5, 2026

CVE-2026-27389 on NVD →

WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon] <= 1.0.1 (unfixed)

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1.

Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Mar 5, 2026

CVE-2026-27390 on NVD →

WeDesignTech Ultimate Booking Addon <= 1.0.3 - Missing Authorization

medium

The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Feb 25, 2026

CVE-2025-69340 on NVD →

WeDesignTech Ultimate Booking Addon <= 1.0.1 - Authentication Bypass

critical

The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, which may include administrators.

CVSS:
9.8
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Feb 23, 2026

CVE-2026-27389 on NVD →

WeDesignTech Ultimate Booking Addon <= 1.0.1 - Authenticated (Subscriber+) Authentication Bypass

high

The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass authentication and log in to other users accounts, which may include admi...

CVSS:
8.8
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Feb 23, 2026

CVE-2026-27390 on NVD →

WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon] <= 1.0.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3.

Affected:
up to 1.0.3
Fix:
No patched version reported
Disclosed:
Jan 6, 2026

CVE-2025-69341 on NVD →

WeDesignTech Ultimate Booking Addon <= 1.0.3 - Missing Authorization

medium

The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Jan 1, 2026

CVE-2025-69341 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database