VYPR

Scheduling Plugin – Online Booking for WordPress

by WordPress

CVEs (3)

  • CVE-2023-4691HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

  • CVE-2024-1634MedJun 18, 2024
    risk 0.42cvss 6.5epss 0.00

    The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cbsb_disconnect_settings' function in all versions up to, and including, 3.5.10. This makes it possible for…

  • CVE-2024-23517MedFeb 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Start Booking Scheduling Plugin – Online Booking for WordPress allows Stored XSS.This issue affects Scheduling Plugin – Online Booking for WordPress: from n/a through 3.5.10.