Booking Calendar

Booking Calendar has 30 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; all 30 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 7 high. 2025 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 15 of the records (50%). Other recurring categories include SQL Injection, Cross-Site Request Forgery (CSRF).

Every one of the 30 issues recorded for Booking Calendar has a vendor fix available, so running the current release closes all known holes.

25 independent researchers contributed these findings, most of them (3) reported by Edwin Molenaar. Booking Calendar is installed on roughly 40,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891015.08.2009Today01.08.20144.3Booking Calendar < 4.1.6 - Cross-Site Request Forgery CVSS 4.3 · 01.08.201401.08.20168.8Booking Calendar <= 6.2 - Cross-Site Request Forgery to SQL Injection CVSS 8.8 · 01.08.20167.2Booking Calendar <= 6.2 - Authenticated (Editor+) SQL Injection CVSS 7.2 · 01.08.20168.8Booking Calendar <= 6.2 - Cross-Site Request Forgery leading to Cross-Site Scripting CVSS 8.8 · 01.08.201628.12.20188.8Booking Calendar <= 8.4.3 - SQL injection CVSS 8.8 · 28.12.201806.12.20216.1Booking Calendar <= 8.9.1 - Reflected Cross-Site Scripting CVSS 6.1 · 06.12.202118.04.20228.5Booking Calendar <= 9.1 - PHP Object Injection via Shortcode CVSS 8.5 · 18.04.202206.09.20225.4Booking Calendar <= 9.2.1 - Cross-Site Request Forgery CVSS 5.4 · 06.09.202220.01.20236.6Booking Calendar <= 9.4.2 - Authenticated (Admin+) SQL Injection CVSS 6.6 · 20.01.202311.09.20236.5Booking Calendar <= 9.7.3 - Unauthenticated Stored Cross-Site Scripting CVSS 6.5 · 11.09.202325.09.20236.4Booking Calendar <= 9.7.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode CVSS 6.4 · 25.09.202307.02.20249.8Booking Calendar <= 9.9 - Unauthenticated SQL Injection CVSS 9.8 · 07.02.202423.07.20246.4WP Booking Calendar <= 10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via bookingform Shortcode CVSS 6.4 · 23.07.202429.08.20246.1WP Booking Calendar <= 10.5 - Reflected Cross-Site Scripting CVSS 6.1 · 29.08.202403.10.20244.4WP Booking Calendar <= 10.6 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 03.10.202417.10.20244.4WP Booking Calendar <= 10.6.2 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 17.10.202414.11.20244.4WP Booking Calendar <= 10.6.4 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 14.11.202413.01.20256.4Booking Calendar <= 10.9.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'booking' Shortcode CVSS 6.4 · 13.01.202511.02.20255.3WP Booking Calendar <= 10.10 - Unauthenticated Post-Confirmation Booking Manipulation CVSS 5.3 · 11.02.202516.05.20256.4Booking Calendar <= 10.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode CVSS 6.4 · 16.05.202527.08.20256.4Booking Calendar <= 10.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 27.08.202513.11.20256.4Booking Calendar <= 10.14.7 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 13.11.202504.12.20256.4Booking Calendar <= 10.14.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via bookingcalendar Shortcode CVSS 6.4 · 04.12.202515.12.20257.5Booking Calendar <= 10.14.8 - Unauthenticated SQL Injection via dates_to_check CVSS 7.5 · 15.12.202508.01.20265.3Booking Calendar <= 10.14.10 - Unauthenticated Sensitive Information Exposure CVSS 5.3 · 08.01.202615.01.20264.3Booking Calendar <= 10.14.11 - Missing Authorization to Sensitive Information Exposure CVSS 4.3 · 15.01.202630.01.20265.3Booking Calendar <= 10.14.13 - Missing Authorization to Unauthenticated Booking Details Exposure CVSS 5.3 · 30.01.202614.02.20264.9Booking Calendar <= 10.14.15 - Authenticated (Editor+) SQL Injection CVSS 4.9 · 14.02.202617.02.20264.3Booking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification CVSS 4.3 · 17.02.202627.07.20267.2Booking Calendar <= 11.4.2 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 27.07.2026

Strategic Overview

Avg CVSSMedium
6.3/ 10
Patch Coverage100%
Open

0

Fixed

30

Get automatic notifications for all Booking Calendar vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2024-1207

Booking Calendar <= 9.9 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

30 records
2026-07-27 00:00CVE-2026-59558
7.2
High
darooYes
2026-02-17 00:00CVE-2026-2230
4.3
Medium
Tarcísio Luchesi De Almeida Silva (Poystick)Yes
2026-02-14 00:00CVE-2026-32358
4.9
Medium
Drew Webber (mcdruid)Yes
2026-01-30 16:06CVE-2026-1431
5.3
Medium
type5afeYes
2026-01-15 16:11CVE-2025-14982
4.3
Medium
shark3yYes
2026-01-08 19:08CVE-2025-14146
5.3
Medium
Filippo DecortesYes
2025-12-15 02:24CVE-2025-14383
7.5
High
Marcin Dudek (dudekmar)Yes
2025-12-04 13:08CVE-2025-12804
6.4
Medium
Muhammad Yudha - DJYes
2025-11-13 00:00CVE-2025-64381
6.4
Medium
Peter ThaleikisYes
2025-08-27 00:00CVE-2025-9346
6.4
Medium
Cody SixteenYes
Showing 1–10 of 30 reports
Booking Calendar banner
Latestv11.7

Booking Calendar

wpdevelop

Author

wpdevelop

4.7(655)
94/100
Last Updated
2026-08-31 (12d ago)
Active Installs
40,000+
Downloads
5,270,362
Requires WP
5.3+
Requires PHP
5.6+
Tested up to
WP 7.1
Created
2009-08-15 (17y ago)

Booking Calendar – Booking Plugin for Appointments, Reservations, Rentals, Events WP Booking Calendar is a flexible WordPress booking plugin for appointments, reservations, rentals, and events. Add a responsive availability calendar and booking form to your website, accept online bookings, and manage them from a modern admin panel. Use Booking Calendar for full-day bookings, time-slot appointments, service scheduling, event registration, inquiry forms, request forms, or even as a simple multi-step contact form with built-in request listing and email notifications. Features | See Demos | FAQ | Get Support Best for appointments, service scheduling, property rentals, equipment rentals, consultations, classes, events, and availability management. Key Features Accept full-day, appointment, and time-slot bookings. Display availability and prevent double bookings. Create customizable booking and inquiry forms. Manage, approve, decline, and edit bookings in WordPress. Send email notifications to administrators and customers. Build multi-step forms with the Drag & Drop Form Builder. Block unavailable dates and time intervals. Synchronize bookings using .ics feeds. Import Google Calendar events. Use responsive booking forms on desktop and mobile. Booking Calendar for Different Businesses Use Booking Calendar for appointment scheduling, service reservations, property and equipment rentals, consultations, classes, events, and other availability-based bookings. Booking Calendar Free includes the essential tools for displaying availability, accepting booking requests, preventing double bookings, sending notifications, and managing reservations in WordPress. Paid editions add multiple booking resources, online payments, seasonal pricing, advanced availability rules, availability search, and MultiUser administration. Full-Day Booking Process in Booking Calendar Free Let visitors complete a full-day property booking through a clear two-step flow. Customers select a property, review available, booked, and pending dates, choose their check-in and check-out dates, enter their contact details, and submit the booking request. The confirmation displays the complete booking summary and provides an option to add the selected dates to Google Calendar. Appointment Booking with Services and Providers Let visitors book appointments through a simple step-by-step flow. Customers choose a Service and an available Provider, select a date and start time, enter their contact details, and submit the booking. The confirmation displays the complete appointment details and provides an option to add the appointment to Google Calendar.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C