Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total9
Critical0
High3
Medium6
Reset
Showing 1-9 of 9 records
Threat Entry Updated 2026-07-01

CVE-2026-12113 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email addresses, phone numbers, appointment comments, and other booking personally identifiable information.

PLUGIN Appointment Booking Calendar

CVE-2026-12113

MEDIUM CVSS 4.3 2026-07-01
Threat Entry Updated 2026-06-22

CVE-2026-1856 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Appointment Booking Calendar

CVE-2026-1856

MEDIUM CVSS 6.4 2026-06-19
Threat Entry Updated 2026-06-18

CVE-2026-12111 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the cpabc_calendar_load2=1 query parameter in wp-admin and only checks is_admin() && current_user_can('edit_posts'), a capability available to Contributor-level users and above. This makes it possible for authenticated attackers with Contributor-level access and above to supply an arbitrary calendar ID via the id parameter and extract customer booking information, including email addresses, names,…

PLUGIN Appointment Booking Calendar

CVE-2026-12111

MEDIUM CVSS 4.3 2026-06-18
Threat Entry Updated 2026-06-17

CVE-2026-4807 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the public exposure of a site-wide reusable nonce. The plugin exposes a public_nonce value through the /wp-json/ssa/v1/embed-inner endpoint, which is accessible to unauthenticated users. The appointment deletion endpoint at /wp-json/ssa/v1/appointments/{id}/delete and /wp-json/ssa/v1/appointments/bulk use a permission check that accepts requests containing both an X-WP-Nonce header (with any arbitrary value) and an X-PUBLIC-Nonce header (with the valid public nonce).…

PLUGIN Appointment Booking Calendar

CVE-2026-4807

MEDIUM CVSS 6.5 2026-05-07
Threat Entry Updated 2025-11-25

CVE-2025-13317 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the plugin exposing an unauthenticated booking processing endpoint (cpabc_appointments_check_IPN_verification) that trusts attacker-supplied payment notifications without verifying their origin, authenticity, or requiring proper authorization checks. This makes it possible for unauthenticated attackers to arbitrarily confirm bookings and insert them into the live calendar via the 'cpabc_ipncheck' parameter, triggering administrative and customer notification emails and disrupting operations.

PLUGIN Appointment Booking Calendar

CVE-2025-13317

MEDIUM CVSS 5.3 2025-11-22
Threat Entry Updated 2025-03-13

CVE-2024-13431 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Appointment Booking Calendar

CVE-2024-13431

MEDIUM CVSS 6.1 2025-03-07
Threat Entry Updated 2025-05-08

CVE-2024-12274 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).

PLUGIN Appointment Booking Calendar

CVE-2024-12274

HIGH CVSS 7.5 2025-01-13
Threat Entry Updated 2025-09-15

CVE-2024-7129 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins

PLUGIN Appointment Booking Calendar

CVE-2024-7129

HIGH CVSS 7.2 2024-09-13
Threat Entry Updated 2025-05-05

CVE-2024-0856 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.

PLUGIN Appointment Booking Calendar

CVE-2024-0856

HIGH CVSS 8.8 2024-03-20
Scroll to top