← WordPress Vulnerabilities
WordPress security by component

Pinpoint Booking System

Pinpoint Booking System is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Apr 08, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: booking-system

CVE-2026-39678: Pinpoint Booking System: A security weakness

Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.9.9.6.5.

PublishedApr 08, 2026
Known safe version> 2.9.9.6.5
Safe version
Apr 08, 2026 CVE-2026-39678
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.9.9.6.5.
> 2.9.9.6.5
CVE5.3
NVDPending
Dec 13, 2024 CVE-2024-54252
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVDPending
Dec 06, 2024 CVE-2024-53815
Pinpoint Booking System: SQL injection
Pinpoint Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Oct 17, 2024 CVE-2024-49304
Pinpoint Booking System: Cross-site scripting
Pinpoint Booking System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Sep 07, 2024 CVE-2024-7112
Pinpoint Booking System – #1 WordPress Booking Plugin: SQL injection
Pinpoint Booking System – #1 WordPress Booking Plugin is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD6.5
Jun 04, 2024 CVE-2023-38520
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Oct 13, 2023 CVE-2023-45270
Booking System: Cross-site request forgery
Booking System is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 06, 2023 CVE-2023-25062
Booking System: Cross-site scripting
Booking System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Oct 10, 2019 CVE-2015-9460
Booking System: SQL injection
Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
May 22, 2014 CVE-2014-3210
Booking System: SQL injection
Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVD6.5