Page 2 of 18 results (0.004 seconds)

CVSS: 8.8EPSS: 1%CPEs: 1EXPL: 1

18 Apr 2022 — The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site. El plugin Booking Calendar para WordPress es vulnerable a una inyección de objetos PHP por medio del shortcode [bookingflextimeline] en versiones hasta la 9.1 incluyéndola. Esto podría ser explotado por usuarios de nivel de suscriptor y supe... • https://www.wordfence.com/blog/2022/04/php-object-injection-in-booking-calendar-plugin • CWE-502: Deserialization of Untrusted Data •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

06 Dec 2021 — The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting El plugin Booking Calendar de WordPress versiones anteriores a 8.9.2, no sanea y escapa del parámetro booking_type antes de devolverlo a una página de administración, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/3ed821a6-c3e2-4964-86f8-d14c4a54708a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

12 Jan 2018 — An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. Se ha descubierto un problema en el plugin booking-calendar 2.1.7 para WordPress. Existe CSRF mediante wp-admin/admin.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/booking-calendar.md • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

11 Jan 2018 — An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][] parameter. Se ha descubierto un problema en el plugin booking-calendar 2.1.7 para WordPress. Existe XSS mediante el parámetro sale_conditions[count][] en wp-admin/admin.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/booking-calendar.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

11 Jan 2018 — An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter. Se ha descubierto un problema en el plugin booking-calendar 2.1.7 para WordPress. Existe XSS mediante el parámetro extra_field1[items][field_item1][price_percent] en wp-admin/admin.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/booking-calendar.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

11 Jan 2018 — An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter. Se ha descubierto un problema en el plugin booking-calendar 2.1.7 para WordPress. Existe XSS mediante el parámetro form_field5[label] en wp-admin/admin.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/booking-calendar.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 1%CPEs: 1EXPL: 0

28 Apr 2017 — Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter. Vulnerabilidad de salto de directorio en Booking Calendar versioes 7.0 y anteriores, que permitiría a un atacante remoto leer ficheros arbitrarios a través de un parámetro captcha_chalange especialmente manipulado. • http://jvn.jp/en/jp/JVN18739672/index.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

28 Apr 2017 — Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Booking Calendar versiones 7.1 y anteriores, que permitiría a un atacante remoto inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://jvn.jp/en/jp/JVN54762089/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •