VYPR

Appointment Booking Calendar Plugin And Scheduling Plugin

by WordPress

Source repositories

CVEs (5)

  • CVE-2023-50841HigDec 28, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin.This issue affects BookingPress – Appointment Booking Calendar Plugin and…

  • CVE-2024-12274HigJan 13, 2025
    risk 0.49cvss 7.5epss 0.01

    The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).

  • CVE-2024-7877MedNov 5, 2024
    risk 0.31cvss 4.8epss 0.00

    The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even…

  • CVE-2024-7876MedNov 5, 2024
    risk 0.31cvss 4.8epss 0.00

    The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even…

  • CVE-2026-12378HigJul 8, 2026
    risk 0.00cvss 8.1epss 0.00

    The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present…