WP Booking System – Booking Calendar Premium < 5.12.8.1 - Missing Authorization
medium
The WP Booking System – Booking Calendar Premium plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 5.12.8.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.12.8.1
- Fixed in:
- 5.12.8.1
- Disclosed:
- Jul 7, 2026
CVE-2026-57367 on NVD →
WP Booking System – Booking Calendar < 1.4 - Cross-Site Scripting
medium
Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.1
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- May 16, 2017
CVE-2017-2168 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database