Booking Calendar Wpdevart Booking Calendar

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Wpdevart Booking Calendar.

By the Year

In 2026 there have been 0 vulnerabilities in Wpdevart Booking Calendar. Last year, in 2025 Booking Calendar had 1 security vulnerability published. Right now, Booking Calendar is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 1 5.30
2024 3 8.37
2023 3 6.87
2022 1 9.80
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 1 0.00

It may take a day or so for new Booking Calendar vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Wpdevart Booking Calendar Security Vulnerabilities

wpdevart Booking Calendar Missing Auth (3.2.30)
CVE-2025-67574 5.3 - Medium - December 09, 2025

Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.30.

AuthZ

SQL Injection Vulnerability in Booking Calendar WpDevArt Plugin
CVE-2024-10856 6.5 - Medium - December 24, 2024

The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the wpdevart_booking_calendar shortcode in versions up to, and including, 3.2.19 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. The vulnerability requires the delete_prev_date theme option being enabled. This makes it possible for authenticated attackers, with contributor-level access or above, to append additional SQL queries into already existing query that can be used to extract sensitive information such as passwords from the database.

SQL Injection

Missing Auth in WpDevArt Booking Cal v3.2.3
CVE-2023-24407 8.8 - High - December 09, 2024

Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.

AuthZ

External Control of Immutable Web Params in WpDevArt Booking Calendar 3.2.3
CVE-2023-24373 9.8 - Critical - June 03, 2024

External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.

Assumed-Immutable Parameter Tampering

SQL Injection in WpDevArt Booking Calendar <3.2.7
CVE-2022-47428 9.8 - Critical - November 06, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.

SQL Injection

WpDevArt Booking Calendar <=3.2.3 XSS via editor+ in Wordpress plugin
CVE-2022-47438 5.4 - Medium - March 29, 2023

Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions.

XSS

CSRF in WpDevArt Booking Calendar Plugin <=3.2.3
CVE-2023-24388 5.4 - Medium - February 17, 2023

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete).

Session Riding

Booking Calendar <=3.2.2 Unauthenticated File Upload RCE
CVE-2022-3982 9.8 - Critical - December 12, 2022

The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE

Unrestricted File Upload

An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress
CVE-2018-10363 - June 13, 2018

An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Wpdevart Booking Calendar or by Wpdevart? Click the Watch button to subscribe.

Wpdevart
Vendor

subscribe