Booking Calendar Wpdevart Booking Calendar

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Wpdevart Booking Calendar.

By the Year

In 2026 there have been 1 vulnerability in Wpdevart Booking Calendar with an average score of 7.1 out of ten. Last year, in 2025 Booking Calendar had 2 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Booking Calendar in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.40.




Year Vulnerabilities Average Score
2026 1 7.10
2025 2 5.70
2024 4 8.08
2023 3 6.87
2022 1 9.80
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 1 0.00

It may take a day or so for new Booking Calendar vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Wpdevart Booking Calendar Security Vulnerabilities

wpdevart Booking Calendar <=3.2.36 Stored XSS Vulnerability
CVE-2026-25435 7.1 - High - March 25, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Stored XSS.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.

XSS

wpdevart Booking Calendar Missing Auth (3.2.30)
CVE-2025-67574 5.3 - Medium - December 09, 2025

Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.30.

AuthZ

WP Booking Calendar 3.2.19/11.2.19 Reflected XSS via calendar_id
CVE-2024-12077 6.1 - Medium - January 07, 2025

The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the calendar_id parameter in all versions up to, and including, 3.2.19 and 11.2.19 respectively, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

XSS

SQL Injection Vulnerability in Booking Calendar WpDevArt Plugin
CVE-2024-10856 6.5 - Medium - December 24, 2024

The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the wpdevart_booking_calendar shortcode in versions up to, and including, 3.2.19 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. The vulnerability requires the delete_prev_date theme option being enabled. This makes it possible for authenticated attackers, with contributor-level access or above, to append additional SQL queries into already existing query that can be used to extract sensitive information such as passwords from the database.

SQL Injection

Missing Auth in WpDevArt Booking Cal v3.2.3
CVE-2023-24407 8.8 - High - December 09, 2024

Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.

AuthZ

Stored XSS via SVG uploads in Booking Calendar WP plugin <=3.2.15
CVE-2024-9504 7.2 - High - November 26, 2024

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

Unrestricted File Upload

External Control of Immutable Web Params in WpDevArt Booking Calendar 3.2.3
CVE-2023-24373 9.8 - Critical - June 03, 2024

External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.

Assumed-Immutable Parameter Tampering

SQL Injection in WpDevArt Booking Calendar <3.2.7
CVE-2022-47428 9.8 - Critical - November 06, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.

SQL Injection

WpDevArt Booking Calendar <=3.2.3 XSS via editor+ in Wordpress plugin
CVE-2022-47438 5.4 - Medium - March 29, 2023

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions.

XSS

CSRF in WpDevArt Booking Calendar Plugin <=3.2.3
CVE-2023-24388 5.4 - Medium - February 17, 2023

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete).

Session Riding

Booking Calendar <=3.2.2 Unauthenticated File Upload RCE
CVE-2022-3982 9.8 - Critical - December 12, 2022

The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE

Unrestricted File Upload

An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress
CVE-2018-10363 - June 13, 2018

An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Wpdevart Booking Calendar or by Wpdevart? Click the Watch button to subscribe.

Wpdevart
Vendor

subscribe