Extension WordPress

Vulnérabilités Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Cette page rassemble les failles publiées pour Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment, leurs plages de versions affectées et les correctifs signalés dans la base locale.

13Vulnérabilités
0Critiques
13Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

13 fiches

CVE-2026-57660 Moyenne · 5,3
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.1 – Missing Authorization

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to,…

Versions affectées

*-2.7.1

Correctif

2.7.2

Publication

26/06/2026

CVE-2026-23972 Moyenne · 4,3
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.6.0 – Missing Authorization

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up…

Versions affectées

*-2.6.0

Correctif

2.6.1

Publication

23/03/2026

CVE-2025-69328 Élevée · 7,5
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Booking and Rental Manager <= 2.5.9 – Authenticated (Contributor+) PHP Object Injection

The Booking and Rental Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.9 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-2.5.9

Correctif

2.6.0

Publication

09/02/2026

CVE-2025-49904 Élevée · 7,2
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Booking and Rental Manager <= 2.5.3 – Unauthenticated Stored Cross-Site Scripting

The Booking and Rental Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

Versions affectées

*-2.5.3

Correctif

2.5.4

Publication

01/11/2025

CVE-2025-64266 Élevée · 7,5
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Booking and Rental Manager <= 2.5.4 – Authenticated (Contributor+) PHP Object Injection

The Booking and Rental Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.4 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-2.5.4

Correctif

2.5.5

Publication

20/09/2025

CVE-2025-27011 Élevée · 8,8
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Booking and Rental Manager <= 2.2.8 – Authenticated (Contributor+) Local File Inclusion

The Booking and Rental Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary…

Versions affectées

*-2.2.8

Correctif

2.2.9

Publication

11/04/2025

CVE-2025-26921 Élevée · 8,8
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.2.6 – Authenticated (Contributor+) PHP Object Injection

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.6 via deserialization of untrusted…

Versions affectées

*-2.2.6

Correctif

2.2.7

Publication

23/02/2025

CVE-2025-22720 Moyenne · 5,3
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress <= 2.2.1 – Missing Authorization

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

15/01/2025

CVE-2024-12412 Moyenne · 6,1
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin <= 2.2.1 – Reflected Cross-Site Scripting

The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘active_tab’ parameter in all versions up to, and including,…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

10/01/2025

CVE-2023-35048 Moyenne · 4,4
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment

Booking and Rental Manager <= 1.2.1 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Booking and Rental Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-1.2.1

Correctif

1.2.2

Publication

13/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités