Known Vulnerabilities for Reservation Plugin by Designthemes
Listed below are 8 of the newest known vulnerabilities associated with "Reservation Plugin" by "Designthemes".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-87966 json | The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthentic... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-17538 json | The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in v... | Not Provided | 2026-10-08 | 2026-10-07 |
| CVE-2026-15229 json | The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allow... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-14550 json | The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its RE... | Not Provided | 2026-08-26 | 2026-08-26 |
| CVE-2026-13328 json | The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status upd... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-11601 json | The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorizati... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-3576 json | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File ... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2025-13968 json | The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode att... | Not Provided | 2026-07-11 | 2026-07-15 |