Extension WordPress
Vulnérabilités Booking Ultra Pro Appointments Booking Calendar Plugin
Cette page rassemble les failles publiées pour Booking Ultra Pro Appointments Booking Calendar Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Booking Ultra Pro Appointments Booking Calendar Plugin
16 fiches
Booking Ultra Pro <= 1.1.23 – Authenticated (Subscriber+) Information Exposure
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.23. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
*-1.1.23
Non indiqué
26/12/2025
Booking Ultra Pro <= 1.1.21 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.1.21
1.1.22
03/09/2025
Booking Ultra Pro <= 1.1.20 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access…
*-1.1.20
1.1.21
05/06/2025
Booking Ultra Pro <= 1.1.19 – Reflected Cross-Site Scripting
The Booking Ultra Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-1.1.19
1.1.20
21/02/2025
Booking Ultra Pro <= 1.1.13 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Updates
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions called via AJAX like save_fields_settings, bup_delete_user_avatar, bup_crop_avatar_user_profile_image, and more in…
*-1.1.13
1.1.14
17/07/2024
Booking Ultra Pro <= 1.1.13 – Unauthenticated Local File Inclusion
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.13. This makes it possible for unauthenticated attackers to include and execute arbitrary files…
*-1.1.13
1.1.14
11/07/2024
Booking Ultra Pro <= 1.1.13 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.1.13
1.1.14
10/07/2024
Booking Ultra Pro <= 1.1.12 – Authenticated (Contributor+) Privilege Escalation
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.12. This makes it possible for authenticated attackers, with contributor-level access and above, to escalate…
*-1.1.12
1.1.13
23/04/2024
Booking Ultra Pro <= 1.1.6 – Missing Authorization via save_fields_settings
The Booking Ultra Pro plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the save_fields_settings function in versions up to, and including, 1.1.6. This makes it possible for authenticated attackers,…
*-1.1.6
1.1.7
12/05/2023
Booking Ultra Pro <= 1.1.8 – Unauthenticated Stored Cross-Site Scripting
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-1.1.8
1.1.9
10/05/2023
Booking Ultra Pro <= 1.1.8 – Reflected Cross-Site Scripting
The Booking Ultra Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-1.1.8
1.1.9
10/05/2023
Booking Ultra Pro <= 1.1.6 – Cross-Site Request Forgery
The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible…
*-1.1.6
1.1.7
21/02/2023
Booking Ultra Pro <= 1.1.8 – Stored Cross-Site Scripting
The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.1.8
1.1.9
29/09/2022
Booking Ultra Pro <= 1.1.6 – Cross-Site Request Forgery
The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on most AJAX actions. This makes it possible for…
*-1.1.6
1.1.7
29/09/2022
Booking Ultra Pro <= 1.1.6 – Cross-Site Request Forgery
The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on most AJAX actions. This makes it possible for…
*-1.1.6
1.1.7
29/09/2022
Booking Ultra Pro <= 1.1.5 – Missing Authorization
The Booking Ultra Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on most AJAX actions in versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber-level…
*-1.1.5
1.1.6
29/09/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.