PatchSiren

wpdevart CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wpdevart CVE published 2026-08-15

CVE-2026-8840

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary reservations as paid or completed, cancel legitimate payments, auto-approve reservatio [truncated]

MEDIUM wpdevart CVE published 2026-07-13

CVE-2026-57778

A Missing Authorization vulnerability exists in wpdevart Booking calendar, Appointment Booking System, affecting versions from n/a through 3.2.36. This issue is related to Exploiting Incorrectly Configured Access Control Security Levels, classified under CWE-862. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users should verify the affected versions and apply patches or updates to ve [truncated]

MEDIUM wpdevart CVE published 2026-07-10

CVE-2026-15289

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpdevart_id’ parameter in all versions up to, and including, 3.2.17. This vulnerability exists due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. An unauthenticated attacker can exploit this vulnerability by appendin [truncated]

MEDIUM WpDevArt CVE published 2026-05-25

CVE-2026-24597

Cross-Site Request Forgery (CSRF) vulnerability in the WpDevArt Organization chart WordPress plugin, affecting versions up to and including 1.7.5. The vulnerability allows attackers to perform unauthorized actions on behalf of authenticated users through crafted requests. The CVSS 3.1 score of 4.3 (Medium severity) reflects network attack vector, low attack complexity, no required privileges, but requires [truncated]