Show filters
47 Total Results
Displaying 41-47 of 47
Sort by:
Attacker Value
Unknown
CVE-2022-0389
Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2021-25061
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.
0
Attacker Value
Unknown
CVE-2021-24726
Disclosure Date: September 13, 2021 (last updated February 23, 2025)
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
0
Attacker Value
Unknown
CVE-2020-29047
Disclosure Date: March 03, 2021 (last updated February 22, 2025)
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
0
Attacker Value
Unknown
CVE-2019-12239
Disclosure Date: May 20, 2019 (last updated November 27, 2024)
The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
0
Attacker Value
Unknown
CVE-2017-17780
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar - Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2, Gravity Forms - Clockwork SMS 2.2, and WP e-Commerce - Clockwork SMS 2.0.5.
0
Attacker Value
Unknown
CVE-2017-2168
Disclosure Date: May 22, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0