Wpdevart Booking Calendar
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Wpdevart Booking Calendar.
By the Year
In 2026 there have been 0 vulnerabilities in Wpdevart Booking Calendar. Last year, in 2025 Booking Calendar had 1 security vulnerability published. Right now, Booking Calendar is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 1 | 5.30 |
| 2024 | 3 | 8.37 |
| 2023 | 3 | 6.87 |
| 2022 | 1 | 9.80 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 0 | 0.00 |
| 2018 | 1 | 0.00 |
It may take a day or so for new Booking Calendar vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Wpdevart Booking Calendar Security Vulnerabilities
wpdevart Booking Calendar Missing Auth (3.2.30)
CVE-2025-67574
5.3 - Medium
- December 09, 2025
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.30.
AuthZ
SQL Injection Vulnerability in Booking Calendar WpDevArt Plugin
CVE-2024-10856
6.5 - Medium
- December 24, 2024
The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the wpdevart_booking_calendar shortcode in versions up to, and including, 3.2.19 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. The vulnerability requires the delete_prev_date theme option being enabled. This makes it possible for authenticated attackers, with contributor-level access or above, to append additional SQL queries into already existing query that can be used to extract sensitive information such as passwords from the database.
SQL Injection
Missing Auth in WpDevArt Booking Cal v3.2.3
CVE-2023-24407
8.8 - High
- December 09, 2024
Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
AuthZ
External Control of Immutable Web Params in WpDevArt Booking Calendar 3.2.3
CVE-2023-24373
9.8 - Critical
- June 03, 2024
External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
Assumed-Immutable Parameter Tampering
SQL Injection in WpDevArt Booking Calendar <3.2.7
CVE-2022-47428
9.8 - Critical
- November 06, 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.
SQL Injection
WpDevArt Booking Calendar <=3.2.3 XSS via editor+ in Wordpress plugin
CVE-2022-47438
5.4 - Medium
- March 29, 2023
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions.
XSS
CSRF in WpDevArt Booking Calendar Plugin <=3.2.3
CVE-2023-24388
5.4 - Medium
- February 17, 2023
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete).
Session Riding
Booking Calendar <=3.2.2 Unauthenticated File Upload RCE
CVE-2022-3982
9.8 - Critical
- December 12, 2022
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
Unrestricted File Upload
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress
CVE-2018-10363
- June 13, 2018
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Wpdevart Booking Calendar or by Wpdevart? Click the Watch button to subscribe.