Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High3
Medium2
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2025-11-25

CVE-2025-13317 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the plugin exposing an unauthenticated booking processing endpoint (cpabc_appointments_check_IPN_verification) that trusts attacker-supplied payment notifications without verifying their origin, authenticity, or requiring proper authorization checks. This makes it possible for unauthenticated attackers to arbitrarily confirm bookings and insert them into the live calendar via the 'cpabc_ipncheck' parameter, triggering administrative and customer notification emails and disrupting operations.

PLUGIN Appointment Booking Calendar

CVE-2025-13317

MEDIUM CVSS 5.3 2025-11-22
Threat Entry Updated 2025-03-13

CVE-2024-13431 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN Appointment Booking Calendar

CVE-2024-13431

MEDIUM CVSS 6.1 2025-03-07
Threat Entry Updated 2025-05-08

CVE-2024-12274 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).

PLUGIN Appointment Booking Calendar

CVE-2024-12274

HIGH CVSS 7.5 2025-01-13
Threat Entry Updated 2025-09-15

CVE-2024-7129 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins

PLUGIN Appointment Booking Calendar

CVE-2024-7129

HIGH CVSS 7.2 2024-09-13
Threat Entry Updated 2025-05-05

CVE-2024-0856 - Appointment Booking Calendar Plugin

The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.

PLUGIN Appointment Booking Calendar

CVE-2024-0856

HIGH CVSS 8.8 2024-03-20
Scroll to top