Vulnerabilities (CVE)

Filtered by vendor Reputeinfosystems Subscribe
Filtered by product Bookingpress
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50841 1 Reputeinfosystems 1 Bookingpress 2024-01-04 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin.This issue affects BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin: from n/a through 1.0.72.
CVE-2023-36507 1 Reputeinfosystems 1 Bookingpress 2023-12-06 N/A 5.3 MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Repute Infosystems BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin.This issue affects BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin: from n/a through 1.0.64.
CVE-2023-6219 1 Reputeinfosystems 1 Bookingpress 2023-12-01 N/A 7.2 HIGH
The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'bookingpress_process_upload' function in versions up to, and including, 1.0.76. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.