VYPR

Booking for Appointments and Events Calendar

by WordPress

CVEs (10)

  • CVE-2026-77705HigSep 12, 2026
    risk 0.47cvss 7.2epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management…

  • CVE-2026-14215MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for…

  • CVE-2026-14216MedAug 26, 2026
    risk 0.42cvss 6.5epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.

  • CVE-2026-10148MedSep 12, 2026
    risk 0.35cvss 6.4epss 0.00

    The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually'…

  • CVE-2026-77689MedSep 12, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never…

  • CVE-2026-14212MedAug 26, 2026
    risk 0.31cvss 4.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password…

  • CVE-2026-14211LowAug 10, 2026
    risk 0.25cvss 3.8epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored…

  • CVE-2026-14213LowAug 13, 2026
    risk 0.24cvss 3.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked…

  • CVE-2026-77704LowAug 29, 2026
    risk 0.18cvss 2.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including…

  • CVE-2026-14214LowAug 1, 2026
    risk 0.18cvss 2.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the…