Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Qué hace este plugin
- Slug:
booked
- Autor: Marcus (aka @msykes)
- 70000+ instalaciones activas
- 84/100 calificación (547 reseñas en wordpress.org)
- 6289255 descargas totales
- En WordPress.org desde 2008-08-06
blockbookingscalendareventstickets
Estado de mantenimiento
- Última actualización: 2026-07-06 1:01pm GMT
- Probado hasta WordPress: 7.0.2
- Requiere PHP: 7.0+
Vulnerabilidades conocidas
3 CVEs conocidos registrados para Booked.
Reportadas entre 2020 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-57747
|
Booked [booked] <= 3.0.0 (unfixed) |
Falsificación de petición en sitios cruzados (CSRF) |
Media
6,5
|
< 3.0.0
|
3.0.0 |
2026-07-02 |
—
|
|
CVE-2026-57746
|
Booked [booked] <= 3.0.0 (unfixed) |
Falta de control de autorización |
Alta
7,1
|
< 3.0.0
|
3.0.0 |
2026-07-02 |
—
|
|
—
|
Booked [booked] <= 3.0.0 (unfixed) |
Elusión de autenticación mediante una ruta o canal alternativo |
Media
6,7
|
< 3.0.0
|
3.0.0 |
2026-01-29 |
—
|
|
CVE-2022-36399
|
Booked [booked] < 2.4.4 |
Exposición de información sensible a un actor no autorizado |
Media
5,3
|
< 2.4.4
|
2.4.4 |
2023-06-27 |
—
|
|
—
|
Booked [booked] < 2.2.6 |
— |
Desconocido
|
< 2.2.6
|
2.2.6 |
2020-02-29 |
—
|
|
—
|
Booked [booked] < 2.2.6 |
— |
Desconocido
|
< 2.2.6
|
2.2.6 |
2020-02-28 |
—
|
|
—
|
Booked [booked] < 2.2.6 |
— |
Desconocido
|
< 2.2.6
|
2.2.6 |
— |
—
|
CVE-2026-57747
The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-57746
The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Booked [booked] <= 3.0.0 (unfixed)
The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Custom-level access and above, to bypass authentication and access other user's accounts.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-36399
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This issue affects Booked - Appointment Booking for WordPress | Calendars: from n/a before 2.4.4.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Booked [booked] < 2.2.6
The Booked plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions hooked via AJAX actions in versions up to, and including, 2.2.5. This makes it possible for authenticated attackers with subscriber-level permissions and above to execute several unauthorized actions.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Booked [booked] < 2.2.6
Broken Authentication vulnerability leading to Sensitive Information disclosure discovered by Noman Riffat in WordPress Booked premium plugin (versions <= 2.2.5).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Booked [booked] < 2.2.6
The plugin allows users to Book Appointment by providing their PII such as Email, Name, Phone Number and Personal Message. The vulnerability allows anyone to Dump all records of users and their appointment details in CSV as an unauthenticated user.
The user also gets registered as a WP User after submitting appointment which introduces more vulnerabilities i.e. a subscriber can approve, delete or modify any appointment and inject Stored XSS.
Edit (WPScanTeam):
February 7th, 2020 - Report Received & Envato Contacted
February 7th, 2020 - Envato Investigating
February 29th, 2020 - v2.2.6 released, fixing the issues
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas