WordPress security by component
Pinpoint Booking System
Plugin description
Pinpoint Booking System is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Apr 08, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
booking-systemLatest vulnerability
CVE-2026-39678: Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.9.9.6.5.
| Safe version |
|
||
|---|---|---|---|
| Apr 08, 2026 |
CVE-2026-39678
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.9.9.6.5.
|
> 2.9.9.6.5 |
CVE5.3
NVDPending
|
| Dec 13, 2024 |
CVE-2024-54252
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVDPending
|
| Dec 06, 2024 |
CVE-2024-53815
Pinpoint Booking System: SQL injection
Pinpoint Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Oct 17, 2024 |
CVE-2024-49304
Pinpoint Booking System: Cross-site scripting
Pinpoint Booking System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Sep 07, 2024 |
CVE-2024-7112
Pinpoint Booking System – #1 WordPress Booking Plugin: SQL injection
Pinpoint Booking System – #1 WordPress Booking Plugin is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD6.5
|
| Jun 04, 2024 |
CVE-2023-38520
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 13, 2023 |
CVE-2023-45270
Booking System: Cross-site request forgery
Booking System is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 06, 2023 |
CVE-2023-25062
Booking System: Cross-site scripting
Booking System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Oct 10, 2019 |
CVE-2015-9460
Booking System: SQL injection
Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| May 22, 2014 |
CVE-2014-3210
Booking System: SQL injection
Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVD6.5
|