Extension WordPress
Vulnérabilités Booktics – Booking Calendar for Appointments and Service Businesses
Cette page rassemble les failles publiées pour Booktics – Booking Calendar for Appointments and Service Businesses, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Booktics – Booking Calendar for Appointments and Service Businesses
4 fiches
Booktics <= 1.0.21 – Unauthenticated PHP Object Injection
The Booktics plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.21 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…
*-1.0.21
1.0.22
29/06/2026
Booktics <= 1.0.16 – Missing Authorization to Get Items via REST API endpoints
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including,…
*-1.0.16
1.0.17
09/03/2026
Booktics <= 1.0.16 – Missing Authorization to Addon Plugin Installation
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'Extension_Controller::update_item_permissions_check' function in all versions up to, and including, 1.0.16.…
*-1.0.16
1.0.17
09/03/2026
Booktics <= 1.0.16 – Missing Authorization
The Booktics plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-1.0.16
1.0.17
02/02/2026
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.