Extension WordPress
Vulnérabilités RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress
Cette page rassemble les failles publiées pour RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress
11 fiches
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1121 – Missing Authorization
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1121. This makes it…
*-4.1121
4.1125
26/05/2026
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress <= 4.1132 – Missing Authorization
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1132. This makes it…
*-4.1132
4.1133
20/04/2026
RepairBuddy <= 4.1132 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via wc_rep_shop_settings_submission AJAX Action
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to…
*-4.1132
4.1133
20/03/2026
RepairBuddy <= 4.1132 – Unauthenticated Information Exposure
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.1132. This makes it possible for unauthenticated attackers to extract sensitive…
*-4.1132
4.1133
26/02/2026
RepairBuddy <= 4.1116 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference due to missing capability checks on the wc_upload_and_save_signature_handler function in all versions up to, and including, 4.1116.…
*-4.1116
4.1121
16/01/2026
CRM WordPress Plugin – RepairBuddy <= 3.8213 – Missing Authorization
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8213. This makes it possible for authenticated attackers,…
*-3.8213
3.8214
04/04/2025
Computer Repair Shop <= 3.8119 – Authenticated (Customer+) Privilege Esclation via Account Takeover
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to account takeover in all versions up to, and including, 3.8119. This makes it possible for authenticated attackers, with Customer-level access and above, to gain access to…
*-3.8119
3.8120
18/12/2024
CRM WordPress Plugin – RepairBuddy <= 3.8120 – Missing Authorization to Account Takeover/Privilege Escalation
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior…
*-3.8120
3.8122
17/12/2024
Computer Repair Shop <= 3.8115 – Unauthenticated Arbitrary File Upload
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.8115. This makes it possible for unauthenticated attackers to upload…
*-3.8115
3.8116
08/11/2024
CRM WordPress Plugin – RepairBuddy <= 3.72 – SQL Injection
The plugin CRM WordPress Plugin for WordPress is vulnerable to SQL injection via several parameters in versions up to, and including, 3.72 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation of the SQL…
*-3.72
3.73
19/05/2022
Computer Repair Shop < 2.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The Computer Repair Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privileges…
[*, 2.0)
2.0
13/01/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.