plugin

Wp Booking System Vulnerabilities

16 known security issues reported for the Wp Booking System WordPress plugin. Most recent disclosed Mar 5, 2026.

1 critical 7 medium

Running Wp Booking System on your site? Check whether your installed version is affected.

Scan your site free

WP Booking System &#8211; Booking Calendar [wp-booking-system] <= 2.0.19.12 (unfixed)

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allows Retrieve Embedded Sensitive Data.This issue affects WP Booking System: from n/a through <= 2.0.19.12.

Affected:
up to 2.0.19.12
Fix:
No patched version reported
Disclosed:
Mar 5, 2026

CVE-2025-68515 on NVD →

WP Booking System – Booking Calendar <= 2.0.19.12 - Unauthenticated Information Exposure

medium

The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.19.12. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.0.19.12
Fixed in:
2.0.19.13
Disclosed:
Mar 4, 2026

CVE-2025-68515 on NVD →

WP Booking System &#8211; Booking Calendar [wp-booking-system] < 2.0.19.3

unknown

[en] Missing Authorization vulnerability in Veribo, Roland Murg WP Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Booking System: from n/a through 2.0.19.2.

Affected:
up to 2.0.19.3
Fixed in:
2.0.19.3
Disclosed:
Dec 9, 2024

CVE-2023-49758 on NVD →

WP Booking System &#8211; Booking Calendar [wp-booking-system] < 2.0.19.11

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Veribo, Roland Murg WP Booking System.This issue affects WP Booking System: from n/a through 2.0.19.10.

Affected:
up to 2.0.19.11
Fixed in:
2.0.19.11
Disclosed:
Oct 29, 2024

CVE-2024-50425 on NVD →

WP Booking System <= 2.0.19.10 - Missing Authorization via wpbs_refresh_calendar_editor

medium

The WP Booking System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpbs_refresh_calendar_editor function in versions up to, and including, 2.0.19.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify...

CVSS:
4.3
Affected:
up to 2.0.19.10
Fixed in:
2.0.19.11
Disclosed:
Oct 24, 2024

CVE-2024-50425 on NVD →

WP Booking System &#8211; Booking Calendar [wp-booking-system] < 2.0.19.9

unknown

[en] The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.19.8. This makes it possible for unauthenticated attackers to inject arb...

Affected:
up to 2.0.19.9
Fixed in:
2.0.19.9
Disclosed:
Sep 14, 2024

CVE-2024-8797 on NVD →

WP Booking System – Booking Calendar <= 2.0.19.8 - Reflected Cross-Site Scripting

medium

The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.19.8. This makes it possible for unauthenticated attackers to inject arbitrar...

CVSS:
6.1
Affected:
up to 2.0.19.8
Fixed in:
2.0.19.9
Disclosed:
Sep 13, 2024

CVE-2024-8797 on NVD →

WP Booking System <= 2.0.19.2 - Missing Authorization

medium

The WP Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpbs_save_calendar_data function in versions up to, and including, 2.0.19.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to save calendar data.

CVSS:
4.3
Affected:
up to 2.0.19.2
Fixed in:
2.0.19.3
Disclosed:
Dec 4, 2023

CVE-2023-49758 on NVD →

WP Booking System &#8211; Booking Calendar [wp-booking-system] < 2.0.18.1

unknown

[en] Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18 versions.

Affected:
up to 2.0.18.1
Fixed in:
2.0.18.1
Disclosed:
Apr 7, 2023

CVE-2023-24402 on NVD →

WP Booking System <= 2.0.18 - Authenticated (Admin+) Stored Cross Site Scripting

medium

The WP Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in pages that will...

CVSS:
4.4
Affected:
up to 2.0.18
Fixed in:
2.0.18.1
Disclosed:
Feb 2, 2023

CVE-2023-24402 on NVD →

WP Booking System &#8211; Booking Calendar [wp-booking-system] < 2.0.15

unknown

[en] The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.

Affected:
up to 2.0.15
Fixed in:
2.0.15
Disclosed:
Jan 17, 2022

CVE-2021-25061 on NVD →

WP Booking System – Booking Calendar <= 2.0.14 - Reflected Cross-Site Scripting

medium

The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.

CVSS:
6.1
Affected:
up to 2.0.15
Fixed in:
2.0.15
Disclosed:
Dec 10, 2021

CVE-2021-25061 on NVD →

WP Booking System Free version < 1.5.2 - Cross-Site Request Forgery

critical

The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.

CVSS:
9.8
Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
May 22, 2019

CVE-2019-12239 on NVD →

WP Booking System &#8211; Booking Calendar [wp-booking-system] < 1.5.2

unknown

[en] The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
May 20, 2019

CVE-2019-12239 on NVD →

WP Booking System &#8211; Booking Calendar [wp-booking-system] < 1.4

unknown

[en] Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
May 22, 2017

CVE-2017-2168 on NVD →

WP Booking System – Booking Calendar < 1.4 - Cross-Site Scripting

medium

Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.1
Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
May 16, 2017

CVE-2017-2168 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database