The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6. This vulnerability allows authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability has a CVSS score of [truncated]
The Appointment Booking Calendar plugin for WordPress has a Sensitive Information Exposure vulnerability (CVE-2026-12111, CVSS Score: 4.3) in versions up to and including 1.4.01. This vulnerability allows authenticated attackers with Contributor-level access or above to extract customer booking information from any calendar managed by the plugin. The issue arises from insufficient authorization and missin [truncated]
A high-severity vulnerability, CVE-2026-48882, was discovered in the WP Time Slots Booking Form plugin, affecting versions up to and including 1.2.50. This vulnerability allows subscribers to inject SQL, potentially leading to unauthorized data access or manipulation. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.5, indicating a high level of severity. The vulnerability [truncated]
CVE-2026-40791 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability in WP Time Slots Booking Form versions <= 1.2.46. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-40791).