Extension WordPress
Vulnérabilités Booking Package
Cette page rassemble les failles publiées pour Booking Package, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Booking Package
10 fiches
Booking Package <= 1.7.20 – Unauthenticated SQL Injection via 'email' Form Parameter
The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient…
*-1.7.20
1.7.21
10/07/2026
Booking Package <= 1.7.16 – Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint,…
*-1.7.16
1.7.17
05/06/2026
Booking Package <= 1.7.06 – Unauthenticated Price Manipulation via 'amount' Parameter
The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the…
*-1.7.06
1.7.07
27/04/2026
Booking Package <= 1.7.06 – Missing Authorization
The Booking Package plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.06. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-1.7.06
1.7.07
21/04/2026
Booking Package <= 1.6.72 – Reflected Cross-Site Scripting via Locale Parameter
The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-1.6.72
1.6.73
18/02/2025
Booking Package <= 1.6.27 – Unauthenticated Price Manipulation
The Booking Package plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 1.6.27. This is due to insufficient validation on the pricing data being passed to the server. This makes it possible…
*-1.6.27
1.6.29
28/03/2024
Booking Package <= 1.6.01 – Reflected Cross-Site Scripting via 'mode'
The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 1.6.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-1.6.01
1.6.02
07/08/2023
Booking Package <= 1.5.98 – Authorization Bypass to Arbitrary Password Reset
The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 due to missing validation in the 'updateUser' function. This allows unauthenticated attackers to reset the email and password of any…
[*, 1.5.99)
1.5.99
05/07/2023
Booking Package <= 1.5.28 – Unauthenticated Sensitive Data Disclosure
The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive…
[*, 1.5.29)
1.5.29
09/03/2022
Booking Package <= 1.5.10 – Reflected Cross-Site Scripting
The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.5.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
[*, 1.5.11)
1.5.11
10/11/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.