booking-wp-plugin records
6 published records for vendor booking-wp-plugin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2023-4691No exploit | Bookly < 22.4 - Admin+ SQLibooking-wp-plugin · bookly · CWE-89 | High7.2 | — | 0.7% | Oct 16, 2023 |
24Monitor | CVE-2018-6891No exploit | Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.booking-wp-plugin · bookly · CWE-79 | Medium6.1 | — | 1.0% | Feb 11, 2018 |
24Monitor | CVE-2023-1172No exploit | The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 booking-wp-plugin · bookly · CWE-79 | Medium6.1 | — | 0.5% | Mar 17, 2023 |
21Monitor | CVE-2021-24930No exploit | Bookly < 20.3.1 - Staff Member Stored Cross-Site Scriptingbooking-wp-plugin · bookly · CWE-79 | Medium5.4 | — | 0.6% | Dec 6, 2021 |
19Monitor | CVE-2023-5209No exploit | Bookly < 22.5 - Admin+ Stored XSSbooking-wp-plugin · bookly · CWE-79 | Medium4.8 | — | 0.5% | Nov 27, 2023 |
19Monitor | CVE-2023-1159No exploit | The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due tbooking-wp-plugin · bookly · CWE-79 | Medium4.8 | — | 0.4% | Jun 2, 2023 |
- CVE-2023-469128Monitor
Bookly < 22.4 - Admin+ SQLi
HighCVSS 7.2No exploitEPSS 1%booking-wp-plugin · booklyOct 16, 2023
- CVE-2018-689124Monitor
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
MediumCVSS 6.1No exploitEPSS 1%booking-wp-plugin · booklyFeb 11, 2018
- CVE-2023-117224Monitor
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5
MediumCVSS 6.1No exploitEPSS 0%booking-wp-plugin · booklyMar 17, 2023
- CVE-2021-2493021Monitor
Bookly < 20.3.1 - Staff Member Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%booking-wp-plugin · booklyDec 6, 2021
- CVE-2023-520919Monitor
Bookly < 22.5 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%booking-wp-plugin · booklyNov 27, 2023
- CVE-2023-115919Monitor
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due t
MediumCVSS 4.8No exploitEPSS 0%booking-wp-plugin · booklyJun 2, 2023