在 WordPress 插件“The Booking for Appointments and Events Calendar”版本 2.4.9 之前,未在执行更改预约状态的操作前校验用户是否具备所需权限,因此允许客户(顾客)为他们所预订的任意预约设置任意状态。这包括批准那些仍处于“待审批”状态的自身预订,以及覆盖同一共享预约上其他客户的预订状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Booking for Appointments and Events Calendar | 1.2.32 ~ 2.4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76548 | Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via F | |
| CVE-2026-10522 | Simple User Registration <= 6.9 - Unauthenticated Privilege Escalation to Administrator | |
| CVE-2026-16061 | Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name} | |
| CVE-2026-16947 | Total Processing Card Payments for WooCommerce <= 7.3 - Unauthenticated SSRF leading to Pa | |
| CVE-2026-16600 | SmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_up | |
| CVE-2026-16259 | Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation | |
| CVE-2026-17520 | Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key | |
| CVE-2026-17522 | Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF | |
| CVE-2026-76546 | Profile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date Shortcode | |
| CVE-2026-19430 | CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via downlo | |
| CVE-2026-18234 | MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet | |
| CVE-2026-18233 | MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion | |
| CVE-2026-76547 | Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export | |
| CVE-2026-81026 | MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN | |
| CVE-2026-76586 | BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment | |
| CVE-2026-77010 | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Jo | |
| CVE-2026-77012 | Icollect <= 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Writ | |
| CVE-2026-77008 | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Setti | |
| CVE-2026-77007 | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButto | |
| CVE-2026-80311 | Stripe Payment Forms by WP Full Pay < 8.5.5 - Cross-Customer Subscription Cancellation via |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet