
CVE-2022-33177 – WordPress Booking Calendar plugin <= 9.2.1 - Cross-Site Request Forgery (CSRF) vulnerabiulity
https://notcve.org/view.php?id=CVE-2022-33177
06 Sep 2022 — Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress leading to Translations Update. Una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en el plugin WPdevelop/Oplugins Booking Calendar versiones anteriores a 9.2.1 incluyéndola en WordPress, conllevando a una actualización de las traducciones. The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.2.1. This is due to mis... • https://patchstack.com/database/vulnerability/booking/wordpress-booking-calendar-plugin-9-2-1-cross-site-request-forgery-csrf-leading-to-translations-update/_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2022-1463 – Booking Calendar <= 9.1 - PHP Object Injection via Shortcode
https://notcve.org/view.php?id=CVE-2022-1463
18 Apr 2022 — The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site. El plugin Booking Calendar para WordPress es vulnerable a una inyección de objetos PHP por medio del shortcode [bookingflextimeline] en versiones hasta la 9.1 incluyéndola. Esto podría ser explotado por usuarios de nivel de suscriptor y supe... • https://www.wordfence.com/blog/2022/04/php-object-injection-in-booking-calendar-plugin • CWE-502: Deserialization of Untrusted Data •

CVE-2021-25040 – Booking Calendar < 8.9.2 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-25040
06 Dec 2021 — The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting El plugin Booking Calendar de WordPress versiones anteriores a 8.9.2, no sanea y escapa del parámetro booking_type antes de devolverlo a una página de administración, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/3ed821a6-c3e2-4964-86f8-d14c4a54708a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-18555 – Booking Calendar - Clockwork SMS <= 1.0.5 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-18555
27 Nov 2017 — The booking-sms plugin before 1.1.0 for WordPress has XSS. El plugin booking-sms anterior a 1.1.0 para WordPress tiene XSS. The Booking Calendar - Clockwork SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘to’ parameter in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performin... • https://wordpress.org/plugins/booking-sms/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-2150
https://notcve.org/view.php?id=CVE-2017-2150
28 Apr 2017 — Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter. Vulnerabilidad de salto de directorio en Booking Calendar versioes 7.0 y anteriores, que permitiría a un atacante remoto leer ficheros arbitrarios a través de un parámetro captcha_chalange especialmente manipulado. • http://jvn.jp/en/jp/JVN18739672/index.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2017-2151
https://notcve.org/view.php?id=CVE-2017-2151
28 Apr 2017 — Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Booking Calendar versiones 7.1 y anteriores, que permitiría a un atacante remoto inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://jvn.jp/en/jp/JVN54762089/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •