Booking Calendar

Wpdevelop · 24 CVEs

CVE-2026-39601
LOW

WordPress Booking Calendar plugin <= 11.8.4 - Race Condition vulnerability

Oct 2, 2026

CVE-2026-93655
MEDIUM

Booking Calendar <= 11.8.3 - Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter

Sep 22, 2026

CVE-2026-92561
MEDIUM

Booking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Parameter

Sep 18, 2026

CVE-2026-92619
HIGH

Booking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter

Sep 18, 2026

CVE-2026-74002
MEDIUM

WordPress Booking Calendar plugin <= 11.7 - Broken Access Control vulnerability

Sep 17, 2026

CVE-2026-59558
HIGH

WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vulnerability

Jul 27, 2026

CVE-2026-32358
HIGH

WordPress Booking Calendar plugin <= 10.14.15 - SQL Injection vulnerability

Mar 13, 2026

CVE-2026-2230
MEDIUM

Booking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings…

Feb 18, 2026

CVE-2026-1431
MEDIUM

Booking Calendar <= 10.14.13 - Missing Authorization to Unauthenticated Booking Details Exposure

Jan 31, 2026

CVE-2025-14982
MEDIUM

Booking Calendar <= 10.14.11 - Missing Authorization to Sensitive Information Exposure

Jan 16, 2026

CVE-2025-14146
MEDIUM

Booking Calendar <= 10.14.10 - Unauthenticated Sensitive Information Exposure

Jan 9, 2026

CVE-2025-14383
HIGH

Booking Calendar <= 10.14.8 - Unauthenticated SQL Injection via dates_to_check

Dec 15, 2025

CVE-2025-12804
MEDIUM

Booking Calendar <= 10.14.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via bookingcalendar Shortcode

Dec 5, 2025

CVE-2025-64381
MEDIUM

WordPress Booking Calendar plugin <= 10.14.7 - Cross Site Scripting (XSS) vulnerability

Nov 13, 2025

CVE-2025-9346
MEDIUM

Booking Calendar <= 10.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 28, 2025

CVE-2025-4669
MEDIUM

Booking Calendar <= 10.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode

May 17, 2025

CVE-2024-13821
MEDIUM

WP Booking Calendar <= 10.10 - Unauthenticated Post-Confirmation Booking Manipulation

Feb 12, 2025

CVE-2024-9306
MEDIUM

WP Booking Calendar <= 10.6 - Authenticated (Admin+) Stored Cross-Site Scripting

Oct 4, 2024

CVE-2024-8274
MEDIUM

WP Booking Calendar <= 10.5 - Reflected Cross-Site Scripting

Aug 30, 2024

CVE-2024-6930
MEDIUM

WP Booking Calendar <= 10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via bookingform Shortcode

Jul 24, 2024

CVE-2024-1207
CRITICAL

Booking Calendar <= 9.9 - Unauthenticated SQL Injection

Feb 8, 2024

CVE-2022-1463
HIGH

Booking Calendar <= 9.1 - PHP Object Injection via Shortcode

May 10, 2022

CVE-2017-2151
MEDIUM

Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitr…

Apr 28, 2017

CVE-2017-2150
MEDIUM

Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary…

Apr 28, 2017

Showing 1 to 24 of 24 CVEs