VYPR

RepairBuddy

by WordPress

CVEs (10)

  • CVE-2024-51793CriNov 11, 2024
    risk 0.65cvss 10.0epss 0.02

    Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Server.This issue affects RepairBuddy: from n/a through <= 3.8115.

  • CVE-2024-56061HigDec 31, 2024
    risk 0.57cvss 8.8epss 0.00

    Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Privilege Escalation.This issue affects RepairBuddy: from n/a through <= 3.8119.

  • CVE-2024-12259HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.01

    The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the…

  • CVE-2026-39584MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.

  • CVE-2026-78291MedAug 24, 2026
    risk 0.34cvss 5.3epss

    Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

  • CVE-2026-39586MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through <= 4.1132.

  • CVE-2026-3567MedMar 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to modify admin-level plugin settings.…

  • CVE-2026-24638MedMay 26, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.

  • CVE-2026-0820MedJan 17, 2026
    risk 0.28cvss 4.3epss 0.00

    The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116. This…

  • CVE-2025-32277MedApr 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RepairBuddy: from n/a through <= 3.8213.