← WordPress Vulnerabilities
WordPress security by component

Booking Activities

Booking Activities is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 8.1.

Plugin slug: booking-activities

CVE-2026-39525: Booking Activities: A security weakness

Booking Activities is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.16.48.1.

PublishedJun 15, 2026
Known safe version1.17.0
Safe version
Jun 15, 2026 CVE-2026-39525
Booking Activities: A security weakness
Booking Activities is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.16.48.1.
1.17.0
CVE6.5
NVDPending
Jan 22, 2026 CVE-2025-67953
Booking Activities: Privilege escalation or authentication bypass
Booking Activities is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.1
NVDPending
Mar 29, 2024 CVE-2024-30449
Booking Activities: Cross-site scripting
Booking Activities is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending