WP Booking System is a niche WordPress plugin focused on appointment and reservation management, with its vulnerability exposure centered on the plugin product itself. The recurring weakness classes—cross-site scripting, cross-site request forgery, and SQL injection—reflect the common attack surface of web-facing form handling and database interaction in WordPress plugins. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpbookingsystem over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12239HIGH The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access. | May 20, 2019 | 7.2 | 24 | NO | NO |
CVE-2017-2168MEDIUM Cross-site scripting vulnerability in WP Booking System Free version prior to version 1.4 and WP Booking System Premium version prior to version 3.7 allows remote attackers to inje | May 22, 2017 | 6.1 | 22 | NO | NO |
CVE-2021-25061MEDIUM The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page. | Jan 17, 2022 | 5.4 | 21 | NO | NO |
CVE-2024-8797MEDIUM The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate | Sep 14, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-24402MEDIUM Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Veribo, Roland Murg WP Booking System – Booking Calendar plugin <= 2.0.18 versions. | Apr 7, 2023 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpbookingsystem.
Media articles that mention a CVE ID that affects a product developed by Wpbookingsystem — matched by CVE ID, not by vendor name.