Extension WordPress

Vulnérabilités Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar

Cette page rassemble les failles publiées pour Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar

5 fiches

CVE-2026-42751 Moyenne · 6,4
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar

Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar <= 2.1.18 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.18 due to insufficient input sanitization and…

Versions affectées

*-2.1.18

Correctif

2.1.19

Publication

29/05/2026

CVE-2025-64275 Moyenne · 6,4
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar

Booking Manager <= 2.1.17 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Booking Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-2.1.17

Correctif

2.1.18

Publication

04/11/2025

CVE-2025-10124 Moyenne · 5,3
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar

Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar <= 2.1.14 – Authenticated (Contributor+) Booking Deletion

The Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'booking-manager-delete' shortcode in all…

Versions affectées

*-2.1.14

Correctif

2.1.15

Publication

19/09/2025

CVE-2023-50840 Élevée · 8,8
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar

Booking Manager <= 2.1.5 – Authenticated(Contributor+) SQL Injection via Shortcode

The Booking Manager plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode attributes in all versions up to 2.1.6 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

Versions affectées

[*, 2.1.6)

Correctif

2.1.6

Publication

21/12/2023

CVE-2023-1977 Moyenne · 6,3
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar

Booking Manager <= 2.0.28 – Authenticated (Subscriber+) Server-Side Request Forgery

The Booking Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.0.28 via the wpbm_get_ssl_page_content() function. This can allow authenticated attackers with subscriber-level permissions and above to make web requests to…

Versions affectées

*-2.0.28

Correctif

2.0.29

Publication

26/04/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités