Extension WordPress
Vulnérabilités WP Simple Booking Calendar
Cette page rassemble les failles publiées pour WP Simple Booking Calendar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Simple Booking Calendar
4 fiches
WP Simple Booking Calendar <= 2.0.13 – Missing Authorization
The WP Simple Booking Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.13. This makes it possible for authenticated attackers, with…
*-2.0.13
2.0.14
16/04/2025
WP Simple Booking Calendar <= 2.0.10 – Reflected Cross-Site Scripting
The WP Simple Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.10. This makes…
*-2.0.10
2.0.11
12/09/2024
WP Simple Booking Calendar <= 2.0.8.4 – Cross-Site Request Forgery
The WP Simple Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.8.4. This is due to missing or incorrect nonce validation on the wpsbc_refresh_calendar_editor function. This makes it…
*-2.0.8.4
2.0.8.5
27/12/2023
WP Simple Booking Calendar <= 2.0.6 – Authenticated SQL Injection
The WP Simple Booking Calendar WordPress plugin before 2.0.7 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
*-2.0.6
2.0.7
06/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.