Extension WordPress
Vulnérabilités Bookit , Booking & Appointment Calendar
Cette page rassemble les failles publiées pour Bookit , Booking & Appointment Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Bookit , Booking & Appointment Calendar
8 fiches
Bookit , Booking & Appointment Calendar <= 2.5.1 – Missing Authorization
The Bookit , Booking & Appointment Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.1. This makes it possible for unauthenticated…
*-2.5.1
2.5.4.1
22/04/2026
Bookit <= 2.5.0 – Missing Authorization to Unauthenticated Settings Update
The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API endpoint in all versions up to, and including, 2.5.0.…
*-2.5.0
2.5.1
15/11/2025
Booking Calendar | Appointment Booking | Bookit <= 2.5.0 – Missing Authorization to Unauthenticated Stripe Connection
The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0.…
*-2.5.0
2.5.1
11/11/2025
BookIt <=2.4.0 – Price Bypass
The Booking Calendar | Appointment Booking | BookIt plugin for WordPress is vulnerable to Price Bypass in versions up to and including 2.4.0. This makes it possible for site owners to make use of premium plugin features without…
*-2.4.0
2.4.1
31/01/2024
BookIt <= 2.4.3 – Authenticated(Administrator+) SQL Injection
The Booking Calendar | Appointment Booking | BookIt plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 2.4.4 (exclusive) due to insufficient escaping on the user supplied parameter and lack…
[*, 2.4.4)
2.4.4
21/12/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.3.9
2.4.0
18/07/2023
BookIt <= 2.3.7 – Authentication Bypass
The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it…
*-2.3.7
2.3.8
20/06/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.2.9)
2.2.9
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.