Extension WordPress
Vulnérabilités VikBooking Hotel Booking Engine & PMS, page 2
Cette page rassemble les failles publiées pour VikBooking Hotel Booking Engine & PMS, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de VikBooking Hotel Booking Engine & PMS
33 fiches
VikBooking Hotel Booking Engine & PMS <= 1.6.1 – Cross-Site Request Forgery in listenTosFieldSavingTask function
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.1. This is due to missing or incorrect nonce validation on the listenTosFieldSavingTask function. This makes…
*-1.6.1
1.6.2
15/02/2023
VikBooking Hotel Booking Engine & PMS <= 1.5.12 – Cross-Site Request Forgery in exec_multitask_widgets function
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.12. This is due to missing or incorrect nonce validation on the exec_multitask_widgets function. This makes…
*-1.5.12
1.6.0
15/02/2023
VikBooking Hotel Booking Engine & PMS <= 1.5.12 – Cross-Site Request Forgery in savetmplfile function
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.12. This is due to missing or incorrect nonce validation on the savetmplfile function. This makes…
*-1.5.12
1.6.0
15/02/2023
VikBooking Hotel Booking Engine & PMS <= 1.5.12 – Cross-Site Request Forgery in saveconfig function
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.12. This is due to missing or incorrect nonce validation on the saveconfig function. This makes…
*-1.5.12
1.6.0
15/02/2023
VikBooking Hotel Booking Engine & PMS <= 1.6.1 – Cross-Site Request Forgery in multiple functions in admin/controller.php
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.1. This is due to missing or incorrect nonce validation on multiple functions in the admin/controller.php…
*-1.6.1
1.6.2
15/02/2023
VikBooking Hotel Booking Engine & PMS <= 1.5.12 – Cross-Site Request Forgery in admin_widgets_welcome function
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.12. This is due to missing or incorrect nonce validation on the admin_widgets_welcome function. This makes…
*-1.5.12
1.6.0
15/02/2023
VikBooking Hotel Booking Engine & PMS <= 1.5.11 – Authenticated (Admin+) Stored Cross-Site Scripting
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.5.11 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 1.5.12)
1.5.12
27/01/2023
VikBooking <= 1.5.8 – Reflected Cross-Site Scripting
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting
[*, 1.5.9)
1.5.9
03/05/2022
VikBooking Hotel Booking Engine & PMS <= 1.5.7 – Admin+ Stored Cross-Site Scripting
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html…
[*, 1.5.8)
1.5.8
21/04/2022
VikBooking Hotel Booking Engine & PMS <= 1.5.8 – Arbitrary File Upload
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code
[*, 1.5.8)
1.5.9
21/04/2022
VikBooking Hotel Booking Engine & PMS <= 1.5.7 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result,…
[*, 1.5.8)
1.5.8
21/04/2022
VikBooking Hotel Booking Engine & PMS <= 1.5.3 – Sensitive Information Exposure
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin
*-1.5.3
1.5.4
18/04/2022
VikBooking Hotel Booking Engine & PMS <= 1.5.3 – Arbitrary File Upload
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin
*-1.5.3
1.5.4
18/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.