Extension WordPress

Vulnérabilités Pinpoint Booking System – Version 2

Cette page rassemble les failles publiées pour Pinpoint Booking System – Version 2, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
0Critiques
13Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Pinpoint Booking System – Version 2

14 fiches

CVE-2024-13235 Moyenne · 6,5
Pinpoint Booking System – Version 2

Pinpoint Booking System – #1 WordPress Booking Plugin <= 2.9.9.5.4 – Authenticated (Subscriber+) SQL Injection

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up to, and including, 2.9.9.5.4 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-2.9.9.5.4

Correctif

2.9.9.6.0

Publication

20/02/2025

CVE-2024-54252 Moyenne · 6,3
Pinpoint Booking System – Version 2

Pinpoint Booking System – #1 WordPress Booking Plugin <= 2.9.9.5.7 – Missing Authorization

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.9.5.7. This makes it possible…

Versions affectées

*-2.9.9.5.7

Correctif

2.9.9.5.8

Publication

05/12/2024

CVE-2024-53815 Moyenne · 6,5
Pinpoint Booking System – Version 2

Pinpoint Booking System <= 2.9.9.5.1 – Authenticated (Subscriber+) SQL Injection

The Pinpoint Booking System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

Versions affectées

*-2.9.9.5.1

Correctif

2.9.9.5.2

Publication

02/12/2024

CVE-2024-49304 Moyenne · 6,1
Pinpoint Booking System – Version 2

Pinpoint Booking System <= 2.9.9.5.7 – Cross-Site Request Forgery to Stored Cross-Site Scripting

The Pinpoint Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.9.5.7. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated…

Versions affectées

*-2.9.9.5.7

Correctif

2.9.9.5.8

Publication

15/10/2024

CVE-2024-7112 Élevée · 8,8
Pinpoint Booking System – Version 2

Pinpoint Booking System <= 2.9.9.5.0- Authenticated (Subscriber+) SQL Injection

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up to, and including, 2.9.9.5.0 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-2.9.9.5.0

Correctif

2.9.9.5.1

Publication

07/09/2024

CVE-2024-3636 Moyenne · 4,4
Pinpoint Booking System – Version 2

Pinpoint Booking System <= 2.9.9.4.7 – Authenticated (Admin+) Stored Cross-Site Scripting

The Pinpoint Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.9.9.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-2.9.9.4.7

Correctif

2.9.9.4.8

Publication

15/07/2024

CVE-2023-45270 Moyenne · 5,4
Pinpoint Booking System – Version 2

Pinpoint Booking System <= 2.9.9.4.0 – Cross-Site Request Forgery via initBackEndAJAX

The Pinpoint Booking System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.9.4.0. This is due to missing or incorrect nonce validation on the initBackEndAJAX function and the functions it calls.…

Versions affectées

*-2.9.9.4.0

Correctif

2.9.9.4.1

Publication

06/10/2023

CVE-2023-25062 Moyenne · 4,4
Pinpoint Booking System – Version 2

Pinpoint Booking System <= 2.9.9.2.8 – Authenticated (Admin+) Stored Cross-Site Scripting

The Pinpoint Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.9.9.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

[*, 2.9.9.2.9)

Correctif

2.9.9.2.9

Publication

02/02/2023

CVE-2023-0220 Élevée · 8,8
Pinpoint Booking System – Version 2

Pinpoint Booking System <= 2.9.9.2.8 – Authenticated (Subscriber+) SQL Injection

The Pinpoint Booking System plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 2.9.9.2.8 due to insufficient escaping on the user supplied attributes and lack of sufficient preparation on…

Versions affectées

*-2.9.9.2.8

Correctif

2.9.9.2.9

Publication

23/01/2023

Vulnérabilité Moyenne · 6,1
Pinpoint Booking System – Version 2

Pinpoint Booking System – #1 WordPress Booking Plugin <= 1.3.1 – Reflected Cross-Site Scripting

The Booking System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eid’ parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.3.1

Correctif

1.4

Publication

04/07/2013

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités