Extension WordPress
Vulnérabilités Booking Calendar, page 2
Cette page rassemble les failles publiées pour Booking Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Booking Calendar
29 fiches
Booking Calendar <= 9.4.2 – Authenticated (Admin+) SQL Injection
The Booking Calendar plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 9.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-9.4.2
9.4.3.1
20/01/2023
Booking Calendar <= 9.2.1 – Cross-Site Request Forgery
The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.2.1. This is due to missing or incorrect nonce validation on the wpbc_translation_buttons_settings_section function. This makes it possible for unauthenticated…
*-9.2.1
9.2.2
06/09/2022
Booking Calendar <= 9.1 – PHP Object Injection via Shortcode
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on…
*-9.1
9.1.1
18/04/2022
Booking Calendar <= 8.9.1 – Reflected Cross-Site Scripting
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
*-8.9.1
8.9.2
06/12/2021
Booking Calendar <= 8.4.3 – SQL injection
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
*-8.4.3
8.4.4
28/12/2018
Booking Calendar <= 6.2 – Authenticated (Editor+) SQL Injection
The Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the booking ID field in versions up to, and including, 6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
[*, 6.2.1)
6.2.1
01/08/2016
Booking Calendar <= 6.2 – Cross-Site Request Forgery to SQL Injection
The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation on the wpdev_get_args_from_request_in_bk_listing function. This makes it possible for unauthenticated…
[*, 6.2.1)
6.2.1
01/08/2016
Booking Calendar <= 6.2 – Cross-Site Request Forgery leading to Cross-Site Scripting
The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation in the plugin's Import tab. This makes it possible for…
[*, 6.2.1)
6.2.1
01/08/2016
Booking Calendar < 4.1.6 – Cross-Site Request Forgery
The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 4.1.6. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to make arbitrary…
[*, 4.1.6)
4.1.6
01/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.