HIGH🇵🇱 Wersja polska

CVE-2024-3022

CVSS 7.2v3.1pub. 2024-04-04upd. 2026-04-08

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in the 'bookingpress_process_upload' function in all versions up to, and including 1.0.87. This allows an authenticated attacker with administrator-level capabilities or higher to upload arbitrary files on the affected site's server, enabling remote code execution.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Reputeinfosystems Bookingpress

    APP
    Reputeinfosystems
    ≤ 1.0.87
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2022-0739CRITICAL9.8PL ✓same product

SQL Injection w pluginie BookingPress dla WordPress (bez uwierzytelnienia)

CVE-2025-31910HIGH7.6same product

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputein...

CVE-2024-6467HIGH8.8same product

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vu...

CVE-2024-6660HIGH8.8same product

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vu...

CVE-2023-51405HIGH8.2same product

Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Pr...