VYPR

RepairBuddy

by WordPress

CVEs (2)

  • CVE-2026-24638MedMay 26, 2026
    risk 0.28cvss 4.3epss

    Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.

  • CVE-2026-0820MedJan 17, 2026
    risk 0.28cvss 4.3epss 0.00

    The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This…