Known vulnerabilities in the Booking plugin
14 security advisories have been published for the Booking plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Booking - Broken Access Control (CVE-2026-5693) MEDIUM
- Booking - Security Vulnerability (CVE-2026-3567) MEDIUM
- Booking - Security Vulnerability (CVE-2026-2230) MEDIUM
- Booking - Cross-Site Scripting (XSS) (CVE-2026-0742) MEDIUM
- Booking - Broken Access Control (CVE-2026-1431) MEDIUM
- Booking - Broken Access Control (CVE-2026-0820) MEDIUM
- Booking - Broken Access Control (CVE-2025-14982) MEDIUM
- Booking - Information Disclosure (CVE-2025-14146) MEDIUM
- Booking - Security Vulnerability (CVE-2025-12842) MEDIUM
- Booking - Cross-Site Scripting (XSS) (CVE-2025-4669) MEDIUM
- Booking - Cross-Site Scripting (XSS) (CVE-2024-13323) MEDIUM
- Booking - Cross-Site Scripting (XSS) (CVE-2024-8274) MEDIUM
- Booking - Cross-Site Scripting (XSS) (CVE-2024-6930) MEDIUM
- Booking - Cross-Site Request Forgery (CSRF) (CVE-2022-33177) MEDIUM