WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Booked?

Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.

Qué hace este plugin

  • Slug: booked
  • Autor: Marcus (aka @msykes)
  • 70000+ instalaciones activas
  • 84/100 calificación (547 reseñas en wordpress.org)
  • 6289255 descargas totales
  • En WordPress.org desde 2008-08-06

blockbookingscalendareventstickets

Estado de mantenimiento

  • Última actualización: 2026-07-06 1:01pm GMT
  • Probado hasta WordPress: 7.0.2
  • Requiere PHP: 7.0+

Vulnerabilidades conocidas

3 CVEs conocidos registrados para Booked. Reportadas entre 2020 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-57747 Booked [booked] <= 3.0.0 (unfixed) Falsificación de petición en sitios cruzados (CSRF) Media 6,5 < 3.0.0 3.0.0 2026-07-02
CVE-2026-57746 Booked [booked] <= 3.0.0 (unfixed) Falta de control de autorización Alta 7,1 < 3.0.0 3.0.0 2026-07-02
Booked [booked] <= 3.0.0 (unfixed) Elusión de autenticación mediante una ruta o canal alternativo Media 6,7 < 3.0.0 3.0.0 2026-01-29
CVE-2022-36399 Booked [booked] < 2.4.4 Exposición de información sensible a un actor no autorizado Media 5,3 < 2.4.4 2.4.4 2023-06-27
Booked [booked] < 2.2.6 Desconocido < 2.2.6 2.2.6 2020-02-29
Booked [booked] < 2.2.6 Desconocido < 2.2.6 2.2.6 2020-02-28
Booked [booked] < 2.2.6 Desconocido < 2.2.6 2.2.6

CVE-2026-57747

The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-57746

The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Booked [booked] <= 3.0.0 (unfixed)

The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Custom-level access and above, to bypass authentication and access other user's accounts.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-36399

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This issue affects Booked - Appointment Booking for WordPress | Calendars: from n/a before 2.4.4.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Booked [booked] < 2.2.6

The Booked plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions hooked via AJAX actions in versions up to, and including, 2.2.5. This makes it possible for authenticated attackers with subscriber-level permissions and above to execute several unauthorized actions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Booked [booked] < 2.2.6

Broken Authentication vulnerability leading to Sensitive Information disclosure discovered by Noman Riffat in WordPress Booked premium plugin (versions <= 2.2.5).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Booked [booked] < 2.2.6

The plugin allows users to Book Appointment by providing their PII such as Email, Name, Phone Number and Personal Message. The vulnerability allows anyone to Dump all records of users and their appointment details in CSV as an unauthenticated user. The user also gets registered as a WP User after submitting appointment which introduces more vulnerabilities i.e. a subscriber can approve, delete or modify any appointment and inject Stored XSS. Edit (WPScanTeam): February 7th, 2020 - Report Received & Envato Contacted February 7th, 2020 - Envato Investigating February 29th, 2020 - v2.2.6 released, fixing the issues

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.