Vulnerabilities > Codepeople > High

DATE CVE VULNERABILITY TITLE RISK
2024-06-09 CVE-2024-33543 Unspecified vulnerability in Codepeople WP Time Slots Booking Form
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.
network
low complexity
codepeople
7.5
2024-01-17 CVE-2022-41790 Unspecified vulnerability in Codepeople WP Time Slots Booking Form
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.
network
low complexity
codepeople
8.8
2022-11-18 CVE-2022-43482 Missing Authorization vulnerability in Codepeople Appointment Booking Calendar
Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.
network
low complexity
codepeople CWE-862
8.8
2020-03-04 CVE-2020-9372 Improper Neutralization of Formula Elements in a CSV File vulnerability in Codepeople Appointment Booking Calendar
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php.
local
low complexity
codepeople CWE-1236
7.8
2019-08-27 CVE-2015-9348 Improper Input Validation vulnerability in Codepeople Sell Downloads
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
network
low complexity
codepeople CWE-20
7.5
2019-08-13 CVE-2018-20964 Cross-Site Request Forgery (CSRF) vulnerability in Codepeople Contact Form Email
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
network
low complexity
codepeople CWE-352
8.8
2017-09-30 CVE-2015-9233 Cross-Site Request Forgery (CSRF) vulnerability in Codepeople CP Contact Form With Paypal
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
network
low complexity
codepeople CWE-352
8.8