Extension WordPress

Vulnérabilités RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

Cette page rassemble les failles publiées pour RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
2Critiques
11Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

11 fiches

CVE-2026-24638 Moyenne · 4,3
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1121 – Missing Authorization

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1121. This makes it…

Versions affectées

*-4.1121

Correctif

4.1125

Publication

26/05/2026

CVE-2026-39584 Moyenne · 4,3
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1132 – Missing Authorization

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1132. This makes it…

Versions affectées

*-4.1132

Correctif

4.1133

Publication

20/04/2026

CVE-2026-3567 Moyenne · 5,3
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

RepairBuddy <= 4.1132 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via wc_rep_shop_settings_submission AJAX Action

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to…

Versions affectées

*-4.1132

Correctif

4.1133

Publication

20/03/2026

CVE-2026-39586 Moyenne · 5,3
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

RepairBuddy <= 4.1132 – Unauthenticated Information Exposure

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1132. This makes it possible for unauthenticated attackers to extract sensitive…

Versions affectées

*-4.1132

Correctif

4.1133

Publication

26/02/2026

CVE-2026-0820 Moyenne · 4,3
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

RepairBuddy <= 4.1116 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116.…

Versions affectées

*-4.1116

Correctif

4.1121

Publication

16/01/2026

CVE-2025-32277 Moyenne · 4,3
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

CRM WordPress Plugin – RepairBuddy <= 3.8213 – Missing Authorization

The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8213. This makes it possible for authenticated attackers,…

Versions affectées

*-3.8213

Correctif

3.8214

Publication

04/04/2025

CVE-2024-56061 Critique · 9,8
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

Computer Repair Shop <= 3.8119 – Authenticated (Customer+) Privilege Esclation via Account Takeover

The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to account takeover in all versions up to, and including, 3.8119. This makes it possible for authenticated attackers, with Customer-level access and above, to gain access to…

Versions affectées

*-3.8119

Correctif

3.8120

Publication

18/12/2024

CVE-2024-12259 Élevée · 8,8
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

CRM WordPress Plugin – RepairBuddy <= 3.8120 – Missing Authorization to Account Takeover/Privilege Escalation

The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior…

Versions affectées

*-3.8120

Correctif

3.8122

Publication

17/12/2024

CVE-2024-51793 Critique · 9,8
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

Computer Repair Shop <= 3.8115 – Unauthenticated Arbitrary File Upload

The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.8115. This makes it possible for unauthenticated attackers to upload…

Versions affectées

*-3.8115

Correctif

3.8116

Publication

08/11/2024

Vulnérabilité Moyenne · 6,6
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

Computer Repair Shop < 2.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The Computer Repair Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privileges…

Versions affectées

[*, 2.0)

Correctif

2.0

Publication

13/01/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités