VendorsRepute InfoSystemsbookingpressall versions
Vulnerabilities

Repute InfoSystems BookingPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2022-0739
BookingPress < 1.0.11 - Unauthenticated SQL Injection
Published 2022-03-21 · Modified
9.8EPSS 0.372
CVE-2023-51405
WordPress BookingPress plugin <= 1.0.74 - Booking Price Manipulation vulnerability
Published 2024-04-24 · Modified
9.8EPSS 0.007
CVE-2024-6467
BookingPress Appointment Booking <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation
Published 2024-07-17 · Modified
8.8EPSS 0.009
CVE-2024-6660
BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload
Published 2024-07-17 · Modified
8.8EPSS 0.006
CVE-2023-50841
WordPress BookingPress Plugin <= 1.0.72 is vulnerable to SQL Injection
Published 2023-12-28 · Modified
8.8EPSS 0.005
CVE-2025-31910
WordPress BookingPress plugin <= 1.1.28 - SQL Injection vulnerability
Published 2025-04-01 · Modified
7.6EPSS 0.004
CVE-2024-3022
BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.87 - Authenticated (Admin+) Arbitrary File Upload
Published 2024-04-04 · Modified
7.2EPSS 0.016
CVE-2023-6219
BookingPress <= 1.0.76 - Authenticated (Administrator+) Arbitrary File Upload
Published 2023-11-28 · Modified
7.2EPSS 0.012
CVE-2024-10540
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection
Published 2024-11-02 · Analyzed
6.5EPSS 0.006
CVE-2024-34799
WordPress BookingPress plugin <= 1.0.82 - Appointment Duration Manipulation vulnerability
Published 2024-06-11 · Analyzed
6.5EPSS 0.004
CVE-2025-24732
WordPress BookingPress Plugin <= 1.1.25 - Cross Site Scripting (XSS) vulnerability
Published 2025-01-24 · Modified
6.5EPSS 0.003
CVE-2024-31296
WordPress BookingPress plugin <= 1.0.81 - Insecure Direct Object References (IDOR) vulnerability
Published 2024-04-07 · Modified
5.4EPSS 0.003
CVE-2022-4340
BookingPress < 1.0.31 - Unauthenticated IDOR in appointment_id
Published 2023-01-02 · Modified
5.3EPSS 0.007
CVE-2023-36507
WordPress BookingPress Plugin <= 1.0.64 is vulnerable to Sensitive Data Exposure
Published 2023-11-30 · Modified
5.3EPSS 0.006