WP Booking System – Booking Calendar [wp-booking-system] <= 2.0.19.12 (unfixed)
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allows Retrieve Embedded Sensitive Data.This issue affects WP Booking System: from n/a through <= 2.0.19.12.
- Affected:
- up to 2.0.19.12
- Fix:
- No patched version reported
- Disclosed:
- Mar 5, 2026
CVE-2025-68515 on NVD →
WP Booking System – Booking Calendar <= 2.0.19.12 - Unauthenticated Information Exposure
medium
The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.19.12. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.0.19.12
- Fixed in:
- 2.0.19.13
- Disclosed:
- Mar 4, 2026
CVE-2025-68515 on NVD →
WP Booking System – Booking Calendar [wp-booking-system] < 2.0.19.3
unknown
[en] Missing Authorization vulnerability in Veribo, Roland Murg WP Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Booking System: from n/a through 2.0.19.2.
- Affected:
- up to 2.0.19.3
- Fixed in:
- 2.0.19.3
- Disclosed:
- Dec 9, 2024
CVE-2023-49758 on NVD →
WP Booking System – Booking Calendar [wp-booking-system] < 2.0.19.11
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Veribo, Roland Murg WP Booking System.This issue affects WP Booking System: from n/a through 2.0.19.10.
- Affected:
- up to 2.0.19.11
- Fixed in:
- 2.0.19.11
- Disclosed:
- Oct 29, 2024
CVE-2024-50425 on NVD →
WP Booking System <= 2.0.19.10 - Missing Authorization via wpbs_refresh_calendar_editor
medium
The WP Booking System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpbs_refresh_calendar_editor function in versions up to, and including, 2.0.19.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify...
- CVSS:
- 4.3
- Affected:
- up to 2.0.19.10
- Fixed in:
- 2.0.19.11
- Disclosed:
- Oct 24, 2024
CVE-2024-50425 on NVD →
WP Booking System – Booking Calendar [wp-booking-system] < 2.0.19.9
unknown
[en] The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.19.8. This makes it possible for unauthenticated attackers to inject arb...
- Affected:
- up to 2.0.19.9
- Fixed in:
- 2.0.19.9
- Disclosed:
- Sep 14, 2024
CVE-2024-8797 on NVD →
WP Booking System – Booking Calendar <= 2.0.19.8 - Reflected Cross-Site Scripting
medium
The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.19.8. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 6.1
- Affected:
- up to 2.0.19.8
- Fixed in:
- 2.0.19.9
- Disclosed:
- Sep 13, 2024
CVE-2024-8797 on NVD →
WP Booking System <= 2.0.19.2 - Missing Authorization
medium
The WP Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpbs_save_calendar_data function in versions up to, and including, 2.0.19.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to save calendar data.
- CVSS:
- 4.3
- Affected:
- up to 2.0.19.2
- Fixed in:
- 2.0.19.3
- Disclosed:
- Dec 4, 2023
CVE-2023-49758 on NVD →
WP Booking System – Booking Calendar [wp-booking-system] < 2.0.18.1
unknown
[en] Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18 versions.
- Affected:
- up to 2.0.18.1
- Fixed in:
- 2.0.18.1
- Disclosed:
- Apr 7, 2023
CVE-2023-24402 on NVD →
WP Booking System <= 2.0.18 - Authenticated (Admin+) Stored Cross Site Scripting
medium
The WP Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in pages that will...
- CVSS:
- 4.4
- Affected:
- up to 2.0.18
- Fixed in:
- 2.0.18.1
- Disclosed:
- Feb 2, 2023
CVE-2023-24402 on NVD →
WP Booking System – Booking Calendar [wp-booking-system] < 2.0.15
unknown
[en] The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- Jan 17, 2022
CVE-2021-25061 on NVD →
WP Booking System – Booking Calendar <= 2.0.14 - Reflected Cross-Site Scripting
medium
The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.
- CVSS:
- 6.1
- Affected:
- up to 2.0.15
- Fixed in:
- 2.0.15
- Disclosed:
- Dec 10, 2021
CVE-2021-25061 on NVD →
WP Booking System Free version < 1.5.2 - Cross-Site Request Forgery
critical
The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
- CVSS:
- 9.8
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- May 22, 2019
CVE-2019-12239 on NVD →
WP Booking System – Booking Calendar [wp-booking-system] < 1.5.2
unknown
[en] The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- May 20, 2019
CVE-2019-12239 on NVD →
WP Booking System – Booking Calendar [wp-booking-system] < 1.4
unknown
[en] Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- May 22, 2017
CVE-2017-2168 on NVD →
WP Booking System – Booking Calendar < 1.4 - Cross-Site Scripting
medium
Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.1
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- May 16, 2017
CVE-2017-2168 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database