cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forbooking booking

Direction: descending
Oct 04, 2026

WP Booking Calendar # CVE-2026-39601

CVE, Research URL

CVE-2026-39601

Application

WP Booking Calendar

Date
Oct 02, 2026
Research Description
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.
Affected versions
max 11.8.4.
Status
vulnerable
Sep 22, 2026

WP Booking Calendar # CVE-2026-93655

CVE, Research URL

CVE-2026-93655

Application

WP Booking Calendar

Date
Sep 22, 2026
Research Description
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 11.8.4.
Status
vulnerable
Sep 18, 2026

WP Booking Calendar # CVE-2026-92561

CVE, Research URL

CVE-2026-92561

Application

WP Booking Calendar

Date
Sep 18, 2026
Research Description
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The nonce check is bypassed by default because the 'booking_is_nonce_at_front_end' option ships disabled, allowing unauthenticated requests to reach the vulnerable sink without any verification.
Affected versions
max 11.8.3.
Status
vulnerable

WP Booking Calendar # CVE-2026-74002

CVE, Research URL

CVE-2026-74002

Application

WP Booking Calendar

Date
Sep 17, 2026
Research Description
Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
Affected versions
max 11.8.
Status
vulnerable

WP Booking Calendar # CVE-2026-92619

CVE, Research URL

CVE-2026-92619

Application

WP Booking Calendar

Date
Sep 18, 2026
Research Description
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via `register_option_policy()`, causing `get_option_policy()` to return an empty policy — bypassing all can_save, force_mode, and allowed_keys checks — for any unregistered option name, including core WordPress options, while an attacker-controlled `data_name` parameter passes through `sanitize_key()` and is written directly to `update_option()` without restriction. This makes it possible for authenticated attackers with Editor-level access and above to escalate their privileges to Administrator by writing core WordPress options such as `default_role=administrator` and `users_can_register=1`, then self-registering a new Administrator account. The nonce check does not meaningfully restrict this attack, as both the nonce value and nonce action are attacker-supplied POST parameters, and a valid nonce is trivially obtainable via `admin-ajax.php?action=rest-nonce`.
Affected versions
max 11.8.3.
Status
vulnerable
Jul 30, 2026

WP Booking Calendar # CVE-2026-59558

CVE, Research URL

CVE-2026-59558

Application

WP Booking Calendar

Date
Jul 27, 2026
Research Description
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
Affected versions
max 11.4.3.
Status
vulnerable
Jun 16, 2026

WP Booking Calendar # bc3451d1e06c42fd0f5692c5064027ede7de932f

Application

WP Booking Calendar

Date
Aug 01, 2014
Research Description
Booking Calendar [booking] < 4.1.6 WordPress Booking Calendar plugin <= 4.1.5 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability discovered by Dylan Irzi in WordPress Booking Calendar plugin (versions <= 4.1.5). Update the WordPress Booking Calendar plugin to the latest available version (at least 4.1.6).
Affected versions
max 4.1.6.
Status
vulnerable

WP Booking Calendar # 3c17b9c7db802bd8184101ed87a1413dd2810488

Application

WP Booking Calendar

Date
Aug 01, 2016
Research Description
Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar plugin <= 6.2 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by ethicalhack3r in WordPress Booking Calendar plugin (versions <= 6.2). Update the WordPress Booking Calendar plugin to the latest available version (at least 6.2.1).
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # 7bd9c02258518f94d77958dbcf1c5fe15a5f3477

Application

WP Booking Calendar

Date
Aug 01, 2016
Research Description
Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar plugin <= 6.2 - SQL Injection (SQLi) vulnerability SQL Injection (SQLi) vulnerability discovered by ethicalhack3r in WordPress Booking Calendar plugin (versions <= 6.2). Update the WordPress Booking Calendar plugin to the latest available version (at least 6.2.1).
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # ca24330cb062d643b83885cff9d7ee3c9a2698a6

Application

WP Booking Calendar

Date
Jul 14, 2023
Research Description
Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin <= 6.2 is vulnerable to SQL Injection Update Booking Calendar Plugin to 6.2.1. Edwin Molenaar discovered and reported this SQL Injection vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 6.2.1.
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # 0189c4d93440d9e4942b4559fba07de2986a58c1

Application

WP Booking Calendar

Date
Sep 25, 2023
Research Description
Booking Calendar [booking] < 9.7.4 Booking Calendar <= 9.7.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 9.7.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 9.7.4.
Status
vulnerable

WP Booking Calendar # b6da51c0-42bd-4847-b32c-b90b95828b27

Application

WP Booking Calendar

Date
-
Research Description
Booking Calendar [booking] < 6.2.1 Booking Calendar &lt;= 6.2 - Reflected Cross-Site Scripting (XSS) The Booking Calendar WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # 3d0a7c76fe184451729ab49296772efbccc1d196

Application

WP Booking Calendar

Date
Aug 01, 2014
Research Description
Booking Calendar [booking] < 4.1.6 Booking Calendar < 4.1.6 - Cross-Site Request Forgery The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 4.1.6. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to make arbitrary calendar changes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 4.1.6.
Status
vulnerable

WP Booking Calendar # 144ce6adab1d866d9f9ab6a93ce0da12c97623a5

Application

WP Booking Calendar

Date
Aug 01, 2016
Research Description
Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin <= 6.2 - Reflected Cross Site Scripting Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # 2644b19e-42ef-45d7-8297-37926f31f883

Application

WP Booking Calendar

Date
-
Research Description
Booking Calendar [booking] < 6.2.1 Booking Calendar &lt;= 6.2 - SQL Injection The Booking Calendar WordPress plugin was affected by a SQL Injection security vulnerability.
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # b23fd45a3f99b282298cb10d009427a8cd1f7640

Application

WP Booking Calendar

Date
Aug 01, 2016
Research Description
Booking Calendar [booking] < 6.2.1 Booking Calendar <= 6.2 - Cross-Site Request Forgery leading to Cross-Site Scripting The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation in the plugin's Import tab. This makes it possible for unauthenticated attackers to to inject arbitrary web scripts that execute in a victim's browser via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # e068351b0a607ae8a00df867aa28c45f5c51ad2e

Application

WP Booking Calendar

Date
Aug 01, 2016
Research Description
Booking Calendar [booking] < 6.2.1 Booking Calendar <= 6.2 - Cross-Site Request Forgery to SQL Injection The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation on the wpdev_get_args_from_request_in_bk_listing function. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # fc4908180385f60ce8ac90a68c6145a8adb4c4ca

Application

WP Booking Calendar

Date
Aug 01, 2023
Research Description
Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS) Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.2.1.
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # f690bc9c-9c42-4a7b-8452-00b870443c58

Application

WP Booking Calendar

Date
-
Research Description
Booking Calendar [booking] < 4.1.6 Booking Calendar &lt;= 4.1.5 - Cross-Site Request Forgery (CSRF) The Booking Calendar WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
Affected versions
max 4.1.6.
Status
vulnerable

WP Booking Calendar # 4e45e98b332a04b36739a62a91bf734597490614

Application

WP Booking Calendar

Date
Aug 01, 2016
Research Description
Booking Calendar [booking] < 6.2.1 Booking Calendar <= 6.2 - Authenticated (Editor+) SQL Injection The Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the booking ID field in versions up to, and including, 6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Editor-level attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 6.2.1.
Status
vulnerable

WP Booking Calendar # 6689d124309d6527b52d145b54cb612bb080eec4

Application

WP Booking Calendar

Date
Jul 14, 2016
Research Description
Booking Calendar [booking] < 6.2.1 WordPress Booking Calendar Plugin 6.2 - SQL Injection Booking Calendar Plugin before 6.2 is prone to a SQL Injection vulnerability. The parameters are not sanitized properly in the wpdev_get_args_from_request_in_bk_listing() function from booking/lib/wpdev-bk-lib.php (line 709). It allows remote attackers to view data from the database by luring the target user into a malicious website. Update Booking Calendar Plugin to 6.2.1.
Affected versions
max 6.2.1.
Status
vulnerable
Jun 13, 2026

WP Booking Calendar # CVE-2025-14146

CVE, Research URL

CVE-2025-14146

Application

WP Booking Calendar

Date
Jan 09, 2026
Research Description
The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default (`booking_is_nonce_at_front_end` option is `'Off'` by default). When the `booking_is_show_popover_in_timeline_front_end` option is enabled (which is the default in demo installations and can be enabled by administrators), it is possible for unauthenticated attackers to extract sensitive booking data including customer names, email addresses, phone numbers, and booking details.
Affected versions
max 10.14.11.
Status
vulnerable
Apr 28, 2026

WP Booking Calendar # PSC-2026-64650

PSC, Research URL

PSC-2026-64650

Application

WP Booking Calendar

Date
Apr 28, 2026
Research Description
Booking and reservation plugins operate across a sensitive boundary between public form submission, calendar availability, customer-provided booking data, admin-side reservation management, and in some configurations external calendar synchronization. These plugins often process names, contact details, selected dates, time slots, service requests, event information, and notification templates, while also controlling whether a date or resource can be booked. A weakness in this class of plugin can lead to stored XSS through booking fields, unauthorized booking manipulation, information disclosure through request listings, CSRF against administrators, double-booking logic abuse, or unsafe synchronization behavior. Booking Calendar version 10.15.6 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64650, confirming that the plugin was reviewed from a secure code perspective with attention to the most common exploitation paths for booking, appointment, reservation, calendar, and form-management plugins.
Affected versions
Min 11.8.4, max 11.8.4.
Status
SAFE & CERTIFIED
Apr 23, 2026

WP Booking Calendar # CVE-2025-9346

CVE, Research URL

CVE-2025-9346

Application

WP Booking Calendar

Date
Aug 28, 2025
Research Description
The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 10.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 10.14.2.
Status
vulnerable
Apr 14, 2026

WP Booking Calendar # CVE-2026-2230

CVE, Research URL

CVE-2026-2230

Application

WP Booking Calendar

Date
Feb 18, 2026
Research Description
The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, and booking permissions granted by an Administrator, to modify other users' plugin settings, such as booking calendar display options, which can disrupt the booking calendar functionality for the targeted user.
Affected versions
max 10.14.15.
Status
vulnerable
Apr 13, 2026

WP Booking Calendar # CVE-2026-1431

CVE, Research URL

CVE-2026-1431

Application

WP Booking Calendar

Date
Jan 31, 2026
Research Description
The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking information including customer names, phones and emails.
Affected versions
max 10.14.14.
Status
vulnerable
Mar 29, 2026

WP Booking Calendar # CVE-2026-32358

CVE, Research URL

CVE-2026-32358

Application

WP Booking Calendar

Date
Mar 14, 2026
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking Calendar booking allows Blind SQL Injection.This issue affects Booking Calendar: from n/a through <= 10.14.15.
Affected versions
max 10.14.16.
Status
vulnerable
Jan 27, 2026

WP Booking Calendar # CVE-2025-14982

CVE, Research URL

CVE-2025-14982

Application

WP Booking Calendar

Date
Jan 16, 2026
Research Description
The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposure in all versions up to, and including, 10.14.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view all booking records in the database, including personally identifiable information (PII) such as names, email addresses, phone numbers, physical addresses, payment status, booking costs, and booking hashes belonging to other users.
Affected versions
max 10.14.12.
Status
vulnerable
Jan 10, 2026

WP Booking Calendar # CVE-2025-14383

CVE, Research URL

CVE-2025-14383

Application

WP Booking Calendar

Date
Dec 15, 2025
Research Description
The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, and including, 10.14.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 10.14.9.
Status
vulnerable
Dec 11, 2025

WP Booking Calendar # CVE-2025-64381

CVE, Research URL

CVE-2025-64381

Application

WP Booking Calendar

Date
Nov 13, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Calendar booking allows Stored XSS.This issue affects Booking Calendar: from n/a through <= 10.14.7.
Affected versions
max 10.14.8.
Status
vulnerable

WP Booking Calendar # CVE-2025-12804

CVE, Research URL

CVE-2025-12804

Application

WP Booking Calendar

Date
Dec 05, 2025
Research Description
The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 10.14.7.
Status
vulnerable
May 18, 2025

WP Booking Calendar # CVE-2025-4669

CVE, Research URL

CVE-2025-4669

Application

WP Booking Calendar

Date
May 17, 2025
Research Description
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 10.11.2.
Status
vulnerable
Feb 15, 2025

WP Booking Calendar # CVE-2024-13821

CVE, Research URL

CVE-2024-13821

Application

WP Booking Calendar

Date
Feb 12, 2025
Research Description
The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.
Affected versions
max 10.10.1.
Status
vulnerable
Jan 15, 2025

WP Booking Calendar # CVE-2024-13323

CVE, Research URL

CVE-2024-13323

Application

WP Booking Calendar

Date
Jan 14, 2025
Research Description
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 10.9.3.
Status
vulnerable
Dec 06, 2024

WP Booking Calendar # CVE-2024-10893

CVE, Research URL

CVE-2024-10893

Application

WP Booking Calendar

Date
Dec 03, 2024
Research Description
The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 10.6.5.
Status
vulnerable
Nov 08, 2024

WP Booking Calendar # CVE-2024-10027

CVE, Research URL

CVE-2024-10027

Application

WP Booking Calendar

Date
Nov 07, 2024
Research Description
The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 10.6.3.
Status
vulnerable
Oct 04, 2024

WP Booking Calendar # CVE-2024-9306

CVE, Research URL

CVE-2024-9306

Application

WP Booking Calendar

Date
Oct 04, 2024
Research Description
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. In addition, site administrators have the option to grant lower-level users with access to manage the plugin's settings which may extend this vulnerability to those users.
Affected versions
max 10.6.1.
Status
vulnerable
Aug 30, 2024

WP Booking Calendar # CVE-2024-8274

CVE, Research URL

CVE-2024-8274

Application

WP Booking Calendar

Date
Aug 30, 2024
Research Description
The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 10.5.1.
Status
vulnerable
Jul 24, 2024

WP Booking Calendar # CVE-2024-6930

CVE, Research URL

CVE-2024-6930

Application

WP Booking Calendar

Date
Jul 24, 2024
Research Description
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions up to, and including, 10.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 10.2.2.
Status
vulnerable
Jun 07, 2024

WP Booking Calendar # CVE-2022-1463

CVE, Research URL

CVE-2022-1463

Application

WP Booking Calendar

Date
May 11, 2022
Research Description
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Affected versions
max 9.1.1.
Status
vulnerable

WP Booking Calendar # CVE-2017-2150

CVE, Research URL

CVE-2017-2150

Application

WP Booking Calendar

Date
Apr 28, 2017
Research Description
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.
Affected versions
max 7.0.
Status
vulnerable

WP Booking Calendar # CVE-2021-25040

CVE, Research URL

CVE-2021-25040

Application

WP Booking Calendar

Date
Jan 03, 2022
Research Description
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Affected versions
max 8.9.2.
Status
vulnerable

WP Booking Calendar # CVE-2018-20556

CVE, Research URL

CVE-2018-20556

Application

WP Booking Calendar

Date
Mar 21, 2019
Research Description
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
Affected versions
max 8.4.5.15.
Status
vulnerable

WP Booking Calendar # CVE-2022-33177

CVE, Research URL

CVE-2022-33177

Application

WP Booking Calendar

Date
Sep 06, 2022
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress leading to Translations Update.
Affected versions
max 9.2.2.
Status
vulnerable

WP Booking Calendar # CVE-2017-2151

CVE, Research URL

CVE-2017-2151

Application

WP Booking Calendar

Date
Apr 28, 2017
Research Description
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected versions
max 7.1.
Status
vulnerable

WP Booking Calendar # CVE-2023-4620

CVE, Research URL

CVE-2023-4620

Application

WP Booking Calendar

Date
Oct 16, 2023
Research Description
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
Affected versions
max 9.7.3.1.
Status
vulnerable

WP Booking Calendar # CVE-2023-51520

CVE, Research URL

CVE-2023-51520

Application

WP Booking Calendar

Date
Feb 01, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.
Affected versions
max 9.7.4.
Status
vulnerable

WP Booking Calendar # CVE-2024-1207

CVE, Research URL

CVE-2024-1207

Application

WP Booking Calendar

Date
Feb 08, 2024
Research Description
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 9.9.1.
Status
vulnerable

WP Booking Calendar # CVE-2023-23991

CVE, Research URL

CVE-2023-23991

Application

WP Booking Calendar

Date
Mar 26, 2024
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3.
Affected versions
max 9.4.3.1.
Status
vulnerable