Stylemixthemes
Stylemixthemes Bookit: vulnerabilidades y CVE
Stylemixthemes Bookit tiene 7 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-89007 | Baja (2.7) | 0.28% | — | 18 sept 2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to… |
| CVE-2026-88995 | Media (5.3) | 0.34% | — | 13 sept 2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers'… |
| CVE-2026-84767 | Media (5.3) | 0.18% | — | 3 sept 2026 | Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. |
| CVE-2025-12841 | Media (5.3) | 0.70% | — | 12 dic 2025 | The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options. |
| CVE-2025-12633 | Alta (7.5) | 0.26% | — | 12 nov 2025 | The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API… |
| CVE-2023-50852 | Alta (7.2) | 0.53% | — | 28 dic 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Booking Calendar | Appointment Booking | BookIt.This issue affects Booking Calendar | Appointment… |
| CVE-2023-2834 | Crítica (9.8) | 1.9% | — | 30 jun 2023 | The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.