+ 34 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-10893
|
Booking Calendar [booking] < 10.6.5 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 10.6.5
|
10.6.5 |
2024-11-14 |
✓ corregido en la última versión
|
|
CVE-2024-10027
|
Booking Calendar [booking] < 10.6.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 10.6.3
|
10.6.3 |
2024-10-17 |
✓ corregido en la última versión
|
|
CVE-2024-9306
|
Booking Calendar [booking] < 10.6.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 10.6.1
|
10.6.1 |
2024-10-03 |
✓ corregido en la última versión
|
|
CVE-2024-8274
|
Booking Calendar [booking] < 10.5.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 10.5.1
|
10.5.1 |
2024-08-29 |
✓ corregido en la última versión
|
|
CVE-2024-6930
|
Booking Calendar [booking] < 10.2.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 10.2.2
|
10.2.2 |
2024-07-23 |
✓ corregido en la última versión
|
|
CVE-2024-1207
|
Booking Calendar [booking] < 9.9.1 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Crítica
9,8
|
< 9.9.1
|
9.9.1 |
2024-02-07 |
✓ corregido en la última versión
|
|
CVE-2023-51520
|
Booking Calendar [booking] < 9.7.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 9.7.4
|
9.7.4 |
2024-02-01 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 9.7.4 |
— |
Desconocido
|
< 9.7.4
|
9.7.4 |
2023-09-25 |
✓ corregido en la última versión
|
|
CVE-2023-4620
|
Booking Calendar [booking] < 9.7.3.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 9.7.3.1
|
9.7.3.1 |
2023-09-11 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
2023-08-01 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
2023-07-14 |
✓ corregido en la última versión
|
|
CVE-2023-23991
|
Booking Calendar [booking] < 9.4.3.1 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,6
|
< 9.4.3.1
|
9.4.3.1 |
2023-01-20 |
✓ corregido en la última versión
|
|
CVE-2022-33177
|
Booking Calendar [booking] < 9.2.2 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
5,4
|
< 9.2.2
|
9.2.2 |
2022-09-06 |
✓ corregido en la última versión
|
|
CVE-2022-1463
|
Booking Calendar [booking] < 9.1.1 |
Deserialización de datos no confiables |
Alta
8,8
|
< 9.1.1
|
9.1.1 |
2022-04-18 |
✓ corregido en la última versión
|
|
CVE-2021-25040
|
Booking Calendar [booking] < 8.9.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 8.9.2
|
8.9.2 |
2021-12-06 |
✓ corregido en la última versión
|
|
CVE-2018-20556
|
Booking Calendar [booking] < 8.4.5.15 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
8,8
|
< 8.4.5.15
|
8.4.5.15 |
2018-12-28 |
✓ corregido en la última versión
|
|
CVE-2017-2150
|
Booking Calendar [booking] <= 7.0 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Media
5,3
|
< 7.0
|
7.0 |
2017-04-20 |
✓ corregido en la última versión
|
|
CVE-2017-2151
|
Booking Calendar [booking] <= 7.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 7.1
|
7.1 |
2017-04-20 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
2016-08-01 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
2016-08-01 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
2016-08-01 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
2016-08-01 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
2016-08-01 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
2016-08-01 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
2016-07-14 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 4.1.6 |
— |
Desconocido
|
< 4.1.6
|
4.1.6 |
2014-08-01 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 4.1.6 |
— |
Desconocido
|
< 4.1.6
|
4.1.6 |
2014-08-01 |
✓ corregido en la última versión
|
|
CVE-2025-4669
|
Booking Calendar [booking] < 10.11.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 10.11.2
|
10.11.2 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-1431
|
Booking Calendar [booking] < 10.14.14 |
— |
Media
5,3
|
< 10.14.14
|
10.14.14 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-2230
|
Booking Calendar [booking] < 10.14.15 |
— |
Desconocido
|
< 10.14.15
|
10.14.15 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 10.14.2 |
— |
Media
6,4
|
< 10.14.2
|
10.14.2 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
— |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 6.2.1 |
— |
Desconocido
|
< 6.2.1
|
6.2.1 |
— |
✓ corregido en la última versión
|
|
—
|
Booking Calendar [booking] < 4.1.6 |
— |
Desconocido
|
< 4.1.6
|
4.1.6 |
— |
✓ corregido en la última versión
|
CVE-2024-10893
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-10027
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-9306
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. In addition, site administrators have the option to grant lower-level users with access to manage the plugin's settings which may extend this vulnerability to those users.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-8274
The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-6930
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions up to, and including, 10.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-1207
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-51520
Update the WordPress Booking Calendar plugin to the latest available version (at least 9.7.4).
Ngô Thiên An (ancorn_ from VNPT-VCI) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.7.4.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Booking Calendar [booking] < 9.7.4
The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 9.7.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-4620
Update the WordPress Booking Calendar plugin to the latest available version (at least 9.7.3.1).
Pablo Sanchez discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.7.3.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Booking Calendar [booking] < 6.2.1
Update the plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.2.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Booking Calendar [booking] < 6.2.1
Update Booking Calendar Plugin to 6.2.1.
Edwin Molenaar discovered and reported this SQL Injection vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 6.2.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-23991
The Booking Calendar plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 9.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrative privileges, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-33177
The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.2.1. This is due to missing or incorrect nonce validation on the wpbc_translation_buttons_settings_section function. This makes it possible for unauthenticated attackers to update translation settings, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-1463
The plugin unserializes user data without being validated first, which could allow attackers to perform PHP object injection attack. If a timeline is published, unauthenticated attackers could perform such attack, otherwise any authenticated could. A suitable POP chain, from another plugin for example, would also be needed for a successful attack
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2021-25040
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2018-20556
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2017-2150
The WordPress plugin "Booking Calendar" provided by wpdevelop contains a directory traversal vulnerability (CWE-22). ASAI Ken reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
CVE-2017-2151
The WordPress plugin "Booking Calendar" provided by wpdevelop contains a stored cross-site scripting vulnerability (CWE-79). Satoshi Takagi of Cryptography Laboratory,Department of Information and Communication Engineering,Tokyo Denki University reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
Booking Calendar [booking] < 6.2.1
Reflected Cross-Site Scripting (XSS) vulnerability discovered by ethicalhack3r in WordPress Booking Calendar plugin (versions <= 6.2).
Update the WordPress Booking Calendar plugin to the latest available version (at least 6.2.1).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Booking Calendar [booking] < 6.2.1
SQL Injection (SQLi) vulnerability discovered by ethicalhack3r in WordPress Booking Calendar plugin (versions <= 6.2).
Update the WordPress Booking Calendar plugin to the latest available version (at least 6.2.1).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Booking Calendar [booking] < 6.2.1
The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation in the plugin's Import tab. This makes it possible for unauthenticated attackers to to inject arbitrary web scripts that execute in a victim's browser via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Booking Calendar [booking] < 6.2.1
The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation on the wpdev_get_args_from_request_in_bk_listing function. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Booking Calendar [booking] < 6.2.1
The Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the booking ID field in versions up to, and including, 6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Editor-level attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Booking Calendar [booking] < 6.2.1
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Booking Calendar [booking] < 6.2.1
Booking Calendar Plugin before 6.2 is prone to a SQL Injection vulnerability. The parameters are not sanitized properly in the wpdev_get_args_from_request_in_bk_listing() function from booking/lib/wpdev-bk-lib.php (line 709). It allows remote attackers to view data from the database by luring the target user into a malicious website.
Update Booking Calendar Plugin to 6.2.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Booking Calendar [booking] < 4.1.6
Cross-Site Request Forgery (CSRF) vulnerability discovered by Dylan Irzi in WordPress Booking Calendar plugin (versions <= 4.1.5).
Update the WordPress Booking Calendar plugin to the latest available version (at least 4.1.6).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Booking Calendar [booking] < 4.1.6
The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 4.1.6. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to make arbitrary calendar changes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-4669
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-1431
The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking information including customer names, phones and emails.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
euvd.enisa.europa.eu
CVE-2026-2230
The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, and booking permissions granted by an Administrator, to modify other users' plugin settings, such as booking calendar display options, which can disrupt the booking calendar functionality for the targeted user.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Booking Calendar [booking] < 10.14.2
The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 10.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Booking Calendar [booking] < 6.2.1
The Booking Calendar WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Booking Calendar [booking] < 6.2.1
The Booking Calendar WordPress plugin was affected by a SQL Injection security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Booking Calendar [booking] < 4.1.6
The Booking Calendar WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Mantén Booking actualizado — 11.4.2 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.