Extension WordPress
Vulnérabilités Appointment Bookings for Zoom GoogleMeet and more – Wappointment
Cette page rassemble les failles publiées pour Appointment Bookings for Zoom GoogleMeet and more – Wappointment, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Appointment Bookings for Zoom GoogleMeet and more – Wappointment
5 fiches
Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 – Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter
The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and including 2.7.6 via the `appointmentkey` parameter due to the appointment `edit_key` ,…
*-2.7.6
2.7.7
01/07/2026
Wappointment <=2.7.2 – Missing Authorization
The Wappointment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.7.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-2.7.6
2.7.7
21/12/2025
Wappointment <= 2.6.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Wappointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.6.9
2.7.0
17/11/2025
Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.6.0 – Authenticated (Administrator+) Server-Side Request Forgery
The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with administrator-level access and…
*-2.6.0
2.6.1
12/04/2024
Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.2.4 – Stored Cross-Site Scripting
The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping.…
*-2.2.4
2.2.5
27/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.