Vulnerabilities and security researches forbooking booking
Direction: descendingOct 04, 2026
WP Booking Calendar # CVE-2026-39601
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 02, 2026
- Research Description
- Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.
- Affected versions
-
max 11.8.4.
- Status
-
vulnerable
Sep 22, 2026
WP Booking Calendar # CVE-2026-93655
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 22, 2026
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 11.8.4.
- Status
-
vulnerable
Sep 18, 2026
WP Booking Calendar # CVE-2026-92561
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 18, 2026
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The nonce check is bypassed by default because the 'booking_is_nonce_at_front_end' option ships disabled, allowing unauthenticated requests to reach the vulnerable sink without any verification.
- Affected versions
-
max 11.8.3.
- Status
-
vulnerable
WP Booking Calendar # CVE-2026-74002
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 17, 2026
- Research Description
- Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
- Affected versions
-
max 11.8.
- Status
-
vulnerable
WP Booking Calendar # CVE-2026-92619
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 18, 2026
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via `register_option_policy()`, causing `get_option_policy()` to return an empty policy — bypassing all can_save, force_mode, and allowed_keys checks — for any unregistered option name, including core WordPress options, while an attacker-controlled `data_name` parameter passes through `sanitize_key()` and is written directly to `update_option()` without restriction. This makes it possible for authenticated attackers with Editor-level access and above to escalate their privileges to Administrator by writing core WordPress options such as `default_role=administrator` and `users_can_register=1`, then self-registering a new Administrator account. The nonce check does not meaningfully restrict this attack, as both the nonce value and nonce action are attacker-supplied POST parameters, and a valid nonce is trivially obtainable via `admin-ajax.php?action=rest-nonce`.
- Affected versions
-
max 11.8.3.
- Status
-
vulnerable
Jul 30, 2026
WP Booking Calendar # CVE-2026-59558
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 27, 2026
- Research Description
- Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
- Affected versions
-
max 11.4.3.
- Status
-
vulnerable
Jun 16, 2026
WP Booking Calendar # bc3451d1e06c42fd0f5692c5064027ede7de932f
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2014
- Research Description
- Booking Calendar [booking] < 4.1.6 WordPress Booking Calendar plugin <= 4.1.5 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability discovered by Dylan Irzi in WordPress Booking Calendar plugin (versions <= 4.1.5). Update the WordPress Booking Calendar plugin to the latest available version (at least 4.1.6).
- Affected versions
-
max 4.1.6.
- Status
-
vulnerable
WP Booking Calendar # 3c17b9c7db802bd8184101ed87a1413dd2810488
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2016
- Research Description
- Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar plugin <= 6.2 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by ethicalhack3r in WordPress Booking Calendar plugin (versions <= 6.2). Update the WordPress Booking Calendar plugin to the latest available version (at least 6.2.1).
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # 7bd9c02258518f94d77958dbcf1c5fe15a5f3477
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2016
- Research Description
- Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar plugin <= 6.2 - SQL Injection (SQLi) vulnerability SQL Injection (SQLi) vulnerability discovered by ethicalhack3r in WordPress Booking Calendar plugin (versions <= 6.2). Update the WordPress Booking Calendar plugin to the latest available version (at least 6.2.1).
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # ca24330cb062d643b83885cff9d7ee3c9a2698a6
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 14, 2023
- Research Description
- Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin <= 6.2 is vulnerable to SQL Injection Update Booking Calendar Plugin to 6.2.1. Edwin Molenaar discovered and reported this SQL Injection vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 6.2.1.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # 0189c4d93440d9e4942b4559fba07de2986a58c1
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 25, 2023
- Research Description
- Booking Calendar [booking] < 9.7.4 Booking Calendar <= 9.7.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 9.7.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 9.7.4.
- Status
-
vulnerable
WP Booking Calendar # b6da51c0-42bd-4847-b32c-b90b95828b27
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Booking Calendar [booking] < 6.2.1 Booking Calendar <= 6.2 - Reflected Cross-Site Scripting (XSS) The Booking Calendar WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # 3d0a7c76fe184451729ab49296772efbccc1d196
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2014
- Research Description
- Booking Calendar [booking] < 4.1.6 Booking Calendar < 4.1.6 - Cross-Site Request Forgery The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 4.1.6. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to make arbitrary calendar changes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 4.1.6.
- Status
-
vulnerable
WP Booking Calendar # 144ce6adab1d866d9f9ab6a93ce0da12c97623a5
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2016
- Research Description
- Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin <= 6.2 - Reflected Cross Site Scripting Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # 2644b19e-42ef-45d7-8297-37926f31f883
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Booking Calendar [booking] < 6.2.1 Booking Calendar <= 6.2 - SQL Injection The Booking Calendar WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # b23fd45a3f99b282298cb10d009427a8cd1f7640
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2016
- Research Description
- Booking Calendar [booking] < 6.2.1 Booking Calendar <= 6.2 - Cross-Site Request Forgery leading to Cross-Site Scripting The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation in the plugin's Import tab. This makes it possible for unauthenticated attackers to to inject arbitrary web scripts that execute in a victim's browser via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # e068351b0a607ae8a00df867aa28c45f5c51ad2e
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2016
- Research Description
- Booking Calendar [booking] < 6.2.1 Booking Calendar <= 6.2 - Cross-Site Request Forgery to SQL Injection The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation on the wpdev_get_args_from_request_in_bk_listing function. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # fc4908180385f60ce8ac90a68c6145a8adb4c4ca
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2023
- Research Description
- Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS) Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.2.1.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # f690bc9c-9c42-4a7b-8452-00b870443c58
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Booking Calendar [booking] < 4.1.6 Booking Calendar <= 4.1.5 - Cross-Site Request Forgery (CSRF) The Booking Calendar WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
- Affected versions
-
max 4.1.6.
- Status
-
vulnerable
WP Booking Calendar # 4e45e98b332a04b36739a62a91bf734597490614
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 01, 2016
- Research Description
- Booking Calendar [booking] < 6.2.1 Booking Calendar <= 6.2 - Authenticated (Editor+) SQL Injection The Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the booking ID field in versions up to, and including, 6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Editor-level attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
WP Booking Calendar # 6689d124309d6527b52d145b54cb612bb080eec4
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 14, 2016
- Research Description
- Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin 6.2 - SQL Injection Booking Calendar Plugin before 6.2 is prone to a SQL Injection vulnerability. The parameters are not sanitized properly in the wpdev_get_args_from_request_in_bk_listing() function from booking/lib/wpdev-bk-lib.php (line 709). It allows remote attackers to view data from the database by luring the target user into a malicious website. Update Booking Calendar Plugin to 6.2.1.
- Affected versions
-
max 6.2.1.
- Status
-
vulnerable
Jun 13, 2026
WP Booking Calendar # CVE-2025-14146
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 09, 2026
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default (`booking_is_nonce_at_front_end` option is `'Off'` by default). When the `booking_is_show_popover_in_timeline_front_end` option is enabled (which is the default in demo installations and can be enabled by administrators), it is possible for unauthenticated attackers to extract sensitive booking data including customer names, email addresses, phone numbers, and booking details.
- Affected versions
-
max 10.14.11.
- Status
-
vulnerable
Apr 28, 2026
WP Booking Calendar # PSC-2026-64650
- PSC, Research URL
- Home page URL
- Application
- Date
- Apr 28, 2026
- Research Description
- Booking and reservation plugins operate across a sensitive boundary between public form submission, calendar availability, customer-provided booking data, admin-side reservation management, and in some configurations external calendar synchronization. These plugins often process names, contact details, selected dates, time slots, service requests, event information, and notification templates, while also controlling whether a date or resource can be booked. A weakness in this class of plugin can lead to stored XSS through booking fields, unauthorized booking manipulation, information disclosure through request listings, CSRF against administrators, double-booking logic abuse, or unsafe synchronization behavior. Booking Calendar version 10.15.6 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64650, confirming that the plugin was reviewed from a secure code perspective with attention to the most common exploitation paths for booking, appointment, reservation, calendar, and form-management plugins.
- Affected versions
-
Min 11.8.4, max 11.8.4.
- Status
-
SAFE & CERTIFIED
Apr 23, 2026
WP Booking Calendar # CVE-2025-9346
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 28, 2025
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 10.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 10.14.2.
- Status
-
vulnerable
Apr 14, 2026
WP Booking Calendar # CVE-2026-2230
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 18, 2026
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, and booking permissions granted by an Administrator, to modify other users' plugin settings, such as booking calendar display options, which can disrupt the booking calendar functionality for the targeted user.
- Affected versions
-
max 10.14.15.
- Status
-
vulnerable
Apr 13, 2026
WP Booking Calendar # CVE-2026-1431
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 31, 2026
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking information including customer names, phones and emails.
- Affected versions
-
max 10.14.14.
- Status
-
vulnerable
Mar 29, 2026
WP Booking Calendar # CVE-2026-32358
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 14, 2026
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking Calendar booking allows Blind SQL Injection.This issue affects Booking Calendar: from n/a through <= 10.14.15.
- Affected versions
-
max 10.14.16.
- Status
-
vulnerable
Jan 27, 2026
WP Booking Calendar # CVE-2025-14982
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 16, 2026
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposure in all versions up to, and including, 10.14.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view all booking records in the database, including personally identifiable information (PII) such as names, email addresses, phone numbers, physical addresses, payment status, booking costs, and booking hashes belonging to other users.
- Affected versions
-
max 10.14.12.
- Status
-
vulnerable
Jan 10, 2026
WP Booking Calendar # CVE-2025-14383
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 15, 2025
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, and including, 10.14.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 10.14.9.
- Status
-
vulnerable
Dec 11, 2025
WP Booking Calendar # CVE-2025-64381
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 13, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Calendar booking allows Stored XSS.This issue affects Booking Calendar: from n/a through <= 10.14.7.
- Affected versions
-
max 10.14.8.
- Status
-
vulnerable
WP Booking Calendar # CVE-2025-12804
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 05, 2025
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 10.14.7.
- Status
-
vulnerable
May 18, 2025
WP Booking Calendar # CVE-2025-4669
- CVE, Research URL
- Home page URL
- Application
- Date
- May 17, 2025
- Research Description
- The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 10.11.2.
- Status
-
vulnerable
Feb 15, 2025
WP Booking Calendar # CVE-2024-13821
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 12, 2025
- Research Description
- The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.
- Affected versions
-
max 10.10.1.
- Status
-
vulnerable
Jan 15, 2025
WP Booking Calendar # CVE-2024-13323
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 14, 2025
- Research Description
- The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 10.9.3.
- Status
-
vulnerable
Dec 06, 2024
WP Booking Calendar # CVE-2024-10893
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 03, 2024
- Research Description
- The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected versions
-
max 10.6.5.
- Status
-
vulnerable
Nov 08, 2024
WP Booking Calendar # CVE-2024-10027
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 07, 2024
- Research Description
- The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected versions
-
max 10.6.3.
- Status
-
vulnerable
Oct 04, 2024
WP Booking Calendar # CVE-2024-9306
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 04, 2024
- Research Description
- The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. In addition, site administrators have the option to grant lower-level users with access to manage the plugin's settings which may extend this vulnerability to those users.
- Affected versions
-
max 10.6.1.
- Status
-
vulnerable
Aug 30, 2024
WP Booking Calendar # CVE-2024-8274
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 30, 2024
- Research Description
- The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 10.5.1.
- Status
-
vulnerable
Jul 24, 2024
WP Booking Calendar # CVE-2024-6930
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 24, 2024
- Research Description
- The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions up to, and including, 10.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 10.2.2.
- Status
-
vulnerable
Jun 07, 2024
WP Booking Calendar # CVE-2022-1463
- CVE, Research URL
- Home page URL
- Application
- Date
- May 11, 2022
- Research Description
- The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
- Affected versions
-
max 9.1.1.
- Status
-
vulnerable
WP Booking Calendar # CVE-2017-2150
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 28, 2017
- Research Description
- Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.
- Affected versions
-
max 7.0.
- Status
-
vulnerable
WP Booking Calendar # CVE-2021-25040
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 03, 2022
- Research Description
- The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
- Affected versions
-
max 8.9.2.
- Status
-
vulnerable
WP Booking Calendar # CVE-2018-20556
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 21, 2019
- Research Description
- SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
- Affected versions
-
max 8.4.5.15.
- Status
-
vulnerable
WP Booking Calendar # CVE-2022-33177
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 06, 2022
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress leading to Translations Update.
- Affected versions
-
max 9.2.2.
- Status
-
vulnerable
WP Booking Calendar # CVE-2017-2151
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 28, 2017
- Research Description
- Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected versions
-
max 7.1.
- Status
-
vulnerable
WP Booking Calendar # CVE-2023-4620
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 16, 2023
- Research Description
- The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
- Affected versions
-
max 9.7.3.1.
- Status
-
vulnerable
WP Booking Calendar # CVE-2023-51520
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 01, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.
- Affected versions
-
max 9.7.4.
- Status
-
vulnerable
WP Booking Calendar # CVE-2024-1207
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 08, 2024
- Research Description
- The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 9.9.1.
- Status
-
vulnerable
WP Booking Calendar # CVE-2023-23991
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 26, 2024
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3.
- Affected versions
-
max 9.4.3.1.
- Status
-
vulnerable