Extension WordPress
Vulnérabilités Easy Appointment Booking & Scheduling System – Webba Booking Calendar
Cette page rassemble les failles publiées pour Easy Appointment Booking & Scheduling System – Webba Booking Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Easy Appointment Booking & Scheduling System – Webba Booking Calendar
11 fiches
Advanced Booking & Appointment System – Webba Booking Calendar <= 6.4.13 – Missing Authorization
The Advanced Booking & Appointment System – Webba Booking Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.4.13. This makes it possible…
*-6.4.13
6.4.14
01/07/2026
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-5.0.57
5.1.8
30/04/2026
Webba Booking <= 6.2.1 – Missing Authorization
The Easy Appointment Booking & Scheduling System – Webba Booking Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.2.1. This makes…
*-6.2.1
6.2.2
15/12/2025
Webba Booking <= 6.0.5 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Webba Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
*-6.0.5
6.0.6
14/08/2025
Webba Booking <= 5.1.20 – Missing Authorization
The Appointment Booking & Scheduling Plugin , Webba Booking Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.1.20. This makes it…
*-5.1.20
5.1.22
16/07/2025
Webba Booking <= 5.1.20 – Cross-Site Request Forgery
The Appointment Booking & Scheduling Plugin , Webba Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.20. This is due to missing or incorrect nonce validation on a…
*-5.1.20
5.1.21
16/07/2025
Appointment & Event Booking Calendar Plugin – Webba Booking <= 5.0.48 – Missing Authorization to Authenticated (Subscriber+) CSS Settings Update
The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_appearance() function in all versions up to, and including, 5.0.48.…
*-5.0.48
5.0.50
23/09/2024
Webba Booking <= 4.5.33 – Cross-Site Request Forgery
The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.33. This is due to missing or incorrect nonce validation on an…
*-4.5.33
5.0
26/12/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-4.5.28
4.5.32
18/07/2023
Webba Booking <= 4.2.21 – Authenticated (Admin+) Stored Cross-Site Scripting
The Webba Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…
*-4.2.21
4.2.22
15/04/2022
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 4.2.18)
4.2.18
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.