← WordPress Vulnerabilities
WordPress security by component

WP BASE Booking

WP BASE Booking is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: wp-base-booking-of-appointments-services-and-events

CVE-2026-59541: WP BASE Booking: Privilege escalation or authentication bypass

WP BASE Booking is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 6.3.1.

PublishedJul 23, 2026
Known safe version6.3.2
Known source slugs: wp-base-booking-of-appointments,-services-and-events, wp-base-booking-of-appointments-services-and-events
Safe version
Jul 23, 2026 CVE-2026-59541
WP BASE Booking: Privilege escalation or authentication bypass
WP BASE Booking is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 6.3.1.
6.3.2
CVE8.8
NVDPending
Jun 15, 2026 CVE-2026-39587
WP BASE Booking: Privilege escalation or authentication bypass
WP BASE Booking is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.9.0.
6.0.0
CVE8.1
NVDPending
Feb 26, 2025 CVE-2024-12737
WP BASE Booking of Appointments, Services and Events: Cross-site scripting
WP BASE Booking of Appointments, Services and Events is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Feb 03, 2025 CVE-2025-22684
WP BASE Booking: Cross-site scripting
WP BASE Booking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Dec 21, 2024 CVE-2024-12558
WP BASE Booking of Appointments, Services and Events: Sensitive information exposure
WP BASE Booking of Appointments, Services and Events is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVDPending
Dec 17, 2024 CVE-2024-12469
WP BASE Booking of Appointments, Services and Events: Cross-site scripting
WP BASE Booking of Appointments, Services and Events is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending