BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin

BookingPress is an appointment booking plugin for WordPress that allows users to set up a complete booking system according to their requirements. It is ideal for businesses in the health and wellness, salon and lifestyle, fitness and gyms, and medical and clinics industries. The plugin is easy to use and can be used by anyone who wants to manage their appointment scheduling online.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.82

    Fixed

    The BookingPress plugin for WordPress can be changed without permission because it does not check for the right capabilities. This can happen in versions 1.0.82 and older. This means that people who ...

    Read More
  • Access violation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.81

    Fixed

    The BookingPress plugin for WordPress, which allows users to schedule appointments and make bookings, has a security issue. This means that anyone with a certain level of access can potentially acces...

    Read More
  • Input validation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.87

    Fixed

    The BookingPress plugin used in WordPress has a security issue where anyone with administrator privileges can upload any type of file onto the website's server. This can allow hackers to remotely run...

    Read More
  • Input validation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.74

    Fixed

    The BookingPress plugin for WordPress is not secure in its current version (1.0.74). An attacker can change the price of an appointment without needing any special authentication. This is because the...

    Read More
  • Input validation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.72

    Fixed

    The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin for WordPress is vulnerable to a type of attack called SQL Injection. This type of attack makes it possible for p...

    Read More
  • Input validation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.76

    Fixed

    The BookingPress plugin for WordPress has a security vulnerability. If someone with administrator-level access or higher uses it, they can upload any type of file to the affected site's server. This ...

    Read More
  • Access violation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.64

    Fixed

    The BookingPress plugin for WordPress is vulnerable to a security issue which could allow an unauthenticated attacker to access sensitive data. The versions of the plugin affected are up to, and incl...

    Read More
  • Input validation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.11

    Fixed

    The BookingPress WordPress plugin had a problem before version 1.0.11 which could have allowed unauthenticated users to inject malicious code into a database. This code could have been used to access ...

    Read More
  • Input validation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.13

    Fixed

    The BookingPress - Appointments Booking Calendar Plugin and Online Scheduling Plugin for WordPress is a tool for managing online bookings. Unfortunately, the plugin has a security flaw that makes it ...

    Read More
  • Access violation vulnerability in BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin 1.0.30

    Fixed

    The BookingPress plugin for WordPress has a security issue in versions up to and including 1.0.30. A user-controlled key called 'appointment_id' does not have enough safeguards in place

    Read More