CVE-2024-13362
Advanced Booking & Appointment System – Webba Booking Calendar
Minimum safe version
6.2.2
Update to 6.2.2 or later to address 13 fixable vulnerabilities
Webba Booking <= 6.2.1 - Missing Authorization
CVE-2025-54729
CVE-2025-54040
CVE-2025-54036
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-8432
WordPress Webba Booking Plugin <= 4.5.33 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Webba Booking Plugin < 4.5.31 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Webba Booking Plugin <= 4.2.21 is vulnerable to Cross Site Scripting (XSS)
WordPress Webba Booking plugin < 4.2.18 - Sensitive Information Disclosure vulnerability
WordPress Webba Booking plugin < 4.2.18 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability