WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon] <= 1.0.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3.
- Affected:
- up to 1.0.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2026
CVE-2025-69340 on NVD →
WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon] <= 1.0.1 (unfixed)
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1.
- Affected:
- up to 1.0.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2026
CVE-2026-27389 on NVD →
WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon] <= 1.0.1 (unfixed)
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1.
- Affected:
- up to 1.0.1
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2026
CVE-2026-27390 on NVD →
WeDesignTech Ultimate Booking Addon <= 1.0.3 - Missing Authorization
medium
The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Feb 25, 2026
CVE-2025-69340 on NVD →
WeDesignTech Ultimate Booking Addon <= 1.0.1 - Authentication Bypass
critical
The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, which may include administrators.
- CVSS:
- 9.8
- Affected:
- up to 1.0.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 23, 2026
CVE-2026-27389 on NVD →
WeDesignTech Ultimate Booking Addon <= 1.0.1 - Authenticated (Subscriber+) Authentication Bypass
high
The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass authentication and log in to other users accounts, which may include admi...
- CVSS:
- 8.8
- Affected:
- up to 1.0.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 23, 2026
CVE-2026-27390 on NVD →
WeDesignTech Ultimate Booking Addon [wedesigntech-ultimate-booking-addon] <= 1.0.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.3.
- Affected:
- up to 1.0.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2026
CVE-2025-69341 on NVD →
WeDesignTech Ultimate Booking Addon <= 1.0.3 - Missing Authorization
medium
The WeDesignTech Ultimate Booking Addon plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Jan 1, 2026
CVE-2025-69341 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database