plugin

Wp Booking System Premium Vulnerabilities

2 known security issues reported for the Wp Booking System Premium WordPress plugin. Most recent disclosed Jul 7, 2026.

2 medium

Running Wp Booking System Premium on your site? Check whether your installed version is affected.

Scan your site free

WP Booking System – Booking Calendar Premium < 5.12.8.1 - Missing Authorization

medium

The WP Booking System – Booking Calendar Premium plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 5.12.8.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.12.8.1
Fixed in:
5.12.8.1
Disclosed:
Jul 7, 2026

CVE-2026-57367 on NVD →

WP Booking System – Booking Calendar < 1.4 - Cross-Site Scripting

medium

Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.1
Affected:
up to 3.7
Fixed in:
3.7
Disclosed:
May 16, 2017

CVE-2017-2168 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database