- Published on
-
Apr 28, 2026
- Research Description
-
Booking and reservation plugins operate across a sensitive boundary between public form submission, calendar availability, customer-provided booking data, admin-side reservation management, and in some configurations external calendar synchronization. These plugins often process names, contact details, selected dates, time slots, service requests, event information, and notification templates, while also controlling whether a date or resource can be booked. A weakness in this class of plugin can lead to stored XSS through booking fields, unauthorized booking manipulation, information disclosure through request listings, CSRF against administrators, double-booking logic abuse, or unsafe synchronization behavior. Booking Calendar version 10.15.6 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64650, confirming that the plugin was reviewed from a secure code perspective with attention to the most common exploitation paths for booking, appointment, reservation, calendar, and form-management plugins.
- Affected versions
-
Min 11.8.4,
max 11.8.4.
Plugin Security Certification
Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Get Plugin Security Certificate
| Previous vulnerability researches |
|
WP Booking Calendar
(CVE-2022-1463)
, Jun 07, 2024
|
|
WP Booking Calendar
(CVE-2017-2150)
, Jun 07, 2024
|
|
WP Booking Calendar
(CVE-2021-25040)
, Jun 07, 2024
|
|
WP Booking Calendar
(CVE-2018-20556)
, Jun 07, 2024
|
|
WP Booking Calendar
(CVE-2022-33177)
, Jun 07, 2024
|
| New vulnerability |
|
Smart Slider 3
(CVE-2026-14876)
, Oct 05, 2026
|
|
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
(CVE-2026-92551)
, Oct 05, 2026
|
|
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
(CVE-2026-92536)
, Oct 05, 2026
|
|
Page Builder by SiteOrigin
(CVE-2026-97256)
, Oct 05, 2026
|
|
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
(CVE-2026-102377)
, Oct 05, 2026
|