Page 3 of 21 results (0.001 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site. El plugin Booking Calendar para WordPress es vulnerable a una inyección de objetos PHP por medio del shortcode [bookingflextimeline] en versiones hasta la 9.1 incluyéndola. Esto podría ser explotado por usuarios de nivel de suscriptor y superior para llamar a objetos PHP arbitrarios en un sitio vulnerable The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site. • https://www.wordfence.com/blog/2022/04/php-object-injection-in-booking-calendar-plugin • CWE-502: Deserialization of Untrusted Data •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting El plugin Booking Calendar de WordPress versiones anteriores a 8.9.2, no sanea y escapa del parámetro booking_type antes de devolverlo a una página de administración, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/3ed821a6-c3e2-4964-86f8-d14c4a54708a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 8%CPEs: 1EXPL: 2

SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter. Vulnerabilidad de inyección SQL en el plugin Booking Calendar 8.4.3 para WordPress permite que atacantes remotos ejecuten comandos SQL arbitrarios mediante el parámetro booking_id. WordPress Booking Calendar version 8.4.3 suffers from a remote SQL injection vulnerability. • https://www.exploit-db.com/exploits/46377 http://packetstormsecurity.com/files/151692/WordPress-Booking-Calendar-8.4.3-SQL-Injection.html https://gist.github.com/B0UG/a750c2c204825453e6faf898ea6d09f6 https://vulners.com/exploitdb/EDB-ID:46377 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices. Se ha descubierto un problema en el plugin de WpDevArt "Booking calendar, Appointment Booking System" 2.2.2 para WordPress. Múltiples parámetros permiten que los atacantes remotos manipulen los valores para que cambien datos como los precios. An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin in versions up to, and including, 2.2.2 for WordPress. • https://gist.github.com/B0UG/68d3161af0c0ec85c615ca7452f9755e • CWE-20: Improper Input Validation •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. Se ha descubierto un problema en el plugin booking-calendar 2.1.7 para WordPress. Existe CSRF mediante wp-admin/admin.php. • https://github.com/d4wner/Vulnerabilities-Report/blob/master/booking-calendar.md https://wpvulndb.com/vulnerabilities/9012 • CWE-352: Cross-Site Request Forgery (CSRF) •