← WordPress Vulnerabilities
WordPress security by component

Booking Package

Booking Package is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jul 11, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: booking-package

CVE-2026-15335: Booking Package: SQL injection

Booking Package is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.7.20.

PublishedJul 11, 2026
Known safe version> 1.7.20
Safe version
Jul 11, 2026 CVE-2026-15335
Booking Package: SQL injection
Booking Package is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.7.20.
> 1.7.20
CVE7.5
NVDPending
Jun 15, 2026 CVE-2026-40774
Booking Package: A security weakness
Booking Package is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.7.06.
1.7.07
CVE7.5
NVDPending
Jun 06, 2026 CVE-2026-9851
Booking Package: Privilege escalation or authentication bypass
Booking Package is affected by privilege escalation or authentication bypass. Exploitation requires at least editor-level access. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 1.7.16.
> 1.7.16
CVE7.2
NVDPending
Apr 28, 2026 CVE-2026-4911
Booking Package: A security weakness
Booking Package is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.7.06.
> 1.7.06
CVE5.3
NVDPending
Jan 05, 2026 CVE-2024-30516
Booking Package: A security weakness
Booking Package is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Feb 19, 2025 CVE-2024-13508
Booking Package: Cross-site scripting
Booking Package is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
May 17, 2024 CVE-2023-37389
Booking Package: Privilege escalation or authentication bypass
Booking Package is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Sep 04, 2023 CVE-2023-39918
Booking Package: Cross-site scripting
Booking Package is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Apr 04, 2022 CVE-2022-0709
Booking Package: A security weakness
Booking Package is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Nov 24, 2021 CVE-2021-20840
Booking Package: Cross-site scripting
Booking Package is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1