Lockme calendars integration

Lockme calendars integration has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Lockme calendars integration has a vendor fix available, so running the current release closes it.

All of these findings were reported by Muhammad Nur Ibnu Hubab. Lockme calendars integration is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Lockme calendars integration vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2026-3367

Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'App ID' Setting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv2.11.1

Lockme calendars integration

lustmored

Author

lustmored

0.0(0)
0/100
Last Updated
2026-04-13 (4mo ago)
Active Installs
10+
Downloads
6,714
Requires WP
6.4+
Requires PHP
8.4+
Tested up to
WP 6.9.7
Created
2017-12-17 (9y ago)

This plugin acts as middleware between your booking system and Lockme OAuth2 API (a.k.a. API 2.0). Usage of this plugin isn’t required, but if you are a Lockme partner and want to seamlessly integrate your booking solution with that found on the Lockme website, it is the easiest way. It will send booking data created via the WordPress site to Lockme and handle messages about bookings from Lockme. Currently, publicly supported calendar systems are: QuickCal (formerly Booked), recommended version 2.0.9 or newer Pinpoint booking system, recommended version 2.6 or newer Booking Calendar Pro WpDevArt version 10.1 or newer (please don’t) Bookly Appointment Booking, recommended version 14.5 or newer Easy Appointments – version 2.1.4 and newer Booking Calendar WP Plugin – only version 6.0.1 tested (also – please don’t) WooCommerce Bookings – version 1.9.1 and newer Appointments by WPMU DEV – version 2.4.0 and newer Appointment Booking Calendar – version 7.2.34 and newer ez Schedule Manager – version 2.2 (once again – please don’t) Amelia – version 7.8 or newer (consider alternatives if possible) BookingPress – version 1.1.49 and newer (discouraged) Other booking systems to be available after porting to API 2.0 and testing. Systems marked as “please don’t” are considered extremely unfriendly to our integration purposes and probably will break upon updating. If you still have a choice, please consider using other booking systems. IMPORTANT! This plugin does its best to work in whatever condition it has to, but it should be noted that the author does not give any warrant regarding data consistency between Lockme and your booking system. If for some reason some bookings are not sent between systems, you should handle it manually. Plugin author does not take any responsibility for such problems. ALSO IMPORTANT! Any integration can break at any time upon updating booking systems. In that case please report this fact immediately, so we can work on a fix. Unfortunately, most booking systems don’t care about extensibility at all, so very dirty hacks are necessary for this plugin to work correctly. We are sorry if your eyes will bleed upon reading some solutions in our code – they’re not clean, but they work in conditions most booking systems create.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C