Istmoplugins develops a niche line of WordPress plugins focused on booking functionality, with a narrow but targeted attack surface in web application access control. The vendor's observed vulnerability pattern centers on missing authorization checks in its Get Bookings plugin, a weakness class common to WordPress extensions that manage restricted data flows. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Istmoplugins over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13677HIGH The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in | Feb 18, 2025 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Istmoplugins.
Media articles that mention a CVE ID that affects a product developed by Istmoplugins — matched by CVE ID, not by vendor name.