plugin

Wp Time Slots Booking Form Vulnerabilities

22 known security issues reported for the Wp Time Slots Booking Form WordPress plugin. Most recent disclosed Jun 2, 2026.

2 high 10 medium 1 low

Running Wp Time Slots Booking Form on your site? Check whether your installed version is affected.

Scan your site free

WP Time Slots Booking Form <= 1.2.50 - Authenticated (Subscriber+) SQL Injection

medium

The WP Time Slots Booking Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.50 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level...

CVSS:
6.5
Affected:
up to 1.2.50
Fixed in:
1.2.51
Disclosed:
Jun 2, 2026

CVE-2026-48882 on NVD →

WP Time Slots Booking Form <= 1.2.46 - Unauthenticated Stored Cross-Site Scripting

high

The WP Time Slots Booking Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...

CVSS:
7.2
Affected:
up to 1.2.46
Fixed in:
1.2.47
Disclosed:
Apr 23, 2026

CVE-2026-40791 on NVD →

Time Slots Booking Form <= 1.2.42 - Missing Authorization

medium

The Time Slots Booking Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.42. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.2.42
Fixed in:
1.2.43
Disclosed:
Mar 2, 2026

CVE-2026-32432 on NVD →

WP Time Slots Booking Form [wp-time-slots-booking-form] <= 1.2.38 (unfixed)

unknown

[en] Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.38.

Affected:
up to 1.2.38
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68569 on NVD →

Time Slots Booking Form <= 1.2.39 - Missing Authorization

medium

The WP Time Slots Booking Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.39. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.2.39
Fixed in:
1.2.40
Disclosed:
Dec 20, 2025

CVE-2025-68569 on NVD →

WP Time Slots Booking Form [wp-time-slots-booking-form] < 1.2.31

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form allows Cross Site Request Forgery. This issue affects WP Time Slots Booking Form: from n/a through 1.2.30.

Affected:
up to 1.2.31
Fixed in:
1.2.31
Disclosed:
Jun 6, 2025

CVE-2025-49332 on NVD →

WP Time Slots Booking Form <= 1.2.30 - Cross-Site Request Forgery

medium

The WP Time Slots Booking Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.30. This is due to missing or incorrect nonce validation on the 'wp_timeslotsbooking' page. This makes it possible for unauthenticated attackers to perform an unauthorized action gra...

CVSS:
4.3
Affected:
up to 1.2.30
Fixed in:
1.2.31
Disclosed:
Jun 5, 2025

CVE-2025-49332 on NVD →

WP Time Slots Booking Form [wp-time-slots-booking-form] < 1.1.83

unknown

[en] Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through 1.1.82.

Affected:
up to 1.1.83
Fixed in:
1.1.83
Disclosed:
Dec 9, 2024

CVE-2023-23895 on NVD →

WP Time Slots Booking Form [wp-time-slots-booking-form] < 1.2.12

unknown

[en] Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.11.

Affected:
up to 1.2.12
Fixed in:
1.2.12
Disclosed:
Jun 10, 2024

CVE-2024-35735 on NVD →

WP Time Slots Booking Form [wp-time-slots-booking-form] < 1.2.07

unknown

[en] Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.

Affected:
up to 1.2.07
Fixed in:
1.2.07
Disclosed:
Jun 9, 2024

CVE-2024-33543 on NVD →

WP Time Slots Booking Form [wp-time-slots-booking-form] < 1.2.11

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople WP Time Slots Booking Form allows Stored XSS.This issue affects WP Time Slots Booking Form: from n/a through 1.2.10.

Affected:
up to 1.2.11
Fixed in:
1.2.11
Disclosed:
Jun 8, 2024

CVE-2024-35734 on NVD →

WP Time Slots Booking Form <= 1.2.10 - Unauthenticated Stored Cross-Site Scripting

high

The WP Time Slots Booking Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenev...

CVSS:
7.2
Affected:
up to 1.2.10
Fixed in:
1.2.11
Disclosed:
Jun 6, 2024

CVE-2024-35734 on NVD →

WP Time Slots Booking Form <= 1.2.11 - Missing Authorization

medium

The WP Time Slots Booking Form plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the data_management() function in versions up to, and including, 1.2.11. This makes it possible for unauthenticated attackers to view slot data.

CVSS:
5.3
Affected:
up to 1.2.11
Fixed in:
1.2.12
Disclosed:
Jun 6, 2024

CVE-2024-35735 on NVD →

WP Time Slots Booking Form <= 1.2.06 - Unauthenticated Price Manipulation

medium

The WP Time Slots Booking Form plugin for WordPress is vulnerable to price manipulation due to insufficient server-side validation of prices in versions up to, and including, 1.2.06. This makes it possible for unauthenticated attackers to alter the price of bookings.

CVSS:
5.3
Affected:
up to 1.2.06
Fixed in:
1.2.07
Disclosed:
Apr 25, 2024

CVE-2024-33543 on NVD →

WP Time Slots Booking Form [wp-time-slots-booking-form] < 1.1.77

unknown

[en] Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.

Affected:
up to 1.1.77
Fixed in:
1.1.77
Disclosed:
Jan 17, 2024

CVE-2022-41790 on NVD →

WP Time Slots Booking Form [wp-time-slots-booking-form] < 1.1.82

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodePeople WP Time Slots Booking Form plugin <= 1.1.81 versions.

Affected:
up to 1.1.82
Fixed in:
1.1.82
Disclosed:
Apr 6, 2023

CVE-2023-23971 on NVD →

WP Time Slots Booking Form <= 1.1.76 - Missing Authorization to Feedback Submission

medium

The WP Time Slots Booking Form plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the cptslotsb_feedback function in versions up to, and including, 1.1.76. This makes it possible for authenticated attackers with subscriber access or higher to submit plugin f...

CVSS:
4.3
Affected:
up to 1.1.76
Fixed in:
1.1.77
Disclosed:
Feb 28, 2023

CVE-2022-41790 on NVD →

WP Time Slots Booking Form <= 1.1.76 - Cross-Site Request Forgery to Feedback Submission

medium

The WP Time Slots Booking Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.76. This is due to missing or incorrect nonce validation on the cptslotsb_feedback function. This makes it possible for unauthenticated attackers to submit plugin feedback on behalf of t...

CVSS:
4.3
Affected:
up to 1.1.76
Fixed in:
1.1.77
Disclosed:
Feb 28, 2023

CVE-2022-41790 on NVD →

WP Time Slots Booking Form <= 1.1.82 - Improper Authorization Checks

medium

The WP Time Slots Booking Form plugin for WordPress is vulnerable to authorization bypass due to improper capability checks throughout the ~/cp-admin-int-add-booking.inc.php file in versions up to, and including, 1.1.83. This makes it possible for authenticated attackers with editor-level privileges to modify some of t...

CVSS:
4.1
Affected:
up to 1.1.82
Fixed in:
1.1.83
Disclosed:
Jan 20, 2023

CVE-2023-23895 on NVD →

WP Time Slots Booking Form <= 1.1.81 - Authenticated (Admin+) Stored Cross Site Scripting

low

The WP Time Slots Booking Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.1.81 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, t...

CVSS:
3.8
Affected:
up to 1.1.81
Fixed in:
1.1.82
Disclosed:
Jan 20, 2023

CVE-2023-23971 on NVD →

WP Time Slots Booking Form [wp-time-slots-booking-form] < 1.1.63

unknown

[en] The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 1.1.63
Fixed in:
1.1.63
Disclosed:
Mar 7, 2022

CVE-2022-0389 on NVD →

WP Time Slots Booking Form <= 1.1.62 - Stored Cross-Site Scripting

medium

The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
5.5
Affected:
up to 1.1.62
Fixed in:
1.1.63
Disclosed:
Feb 2, 2022

CVE-2022-0389 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database