WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Booking?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Booking — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: booking
  • 50000+ instalaciones activas

appointment bookingbooking calendarbooking formcontact formreservations

Estado de mantenimiento

  • Última versión conocida: 11.4.2
  • Requiere PHP: 5.6+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

26 CVEs conocidos registrados para Booking.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-32358 Booking Calendar [booking] < 10.14.16 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,6 < 10.14.16 10.14.16 2026-02-14 ✓ corregido en la última versión
CVE-2025-14982 Booking Calendar [booking] < 10.14.12 Falta de control de autorización Media 4,3 < 10.14.12 10.14.12 2026-01-15 ✓ corregido en la última versión
CVE-2025-14146 Booking Calendar [booking] < 10.14.11 Falta de control de autorización Media 5,3 < 10.14.11 10.14.11 2026-01-08 ✓ corregido en la última versión
CVE-2025-14383 Booking Calendar [booking] < 10.14.9 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,5 < 10.14.9 10.14.9 2025-12-15 ✓ corregido en la última versión
CVE-2025-12804 Booking Calendar [booking] < 10.14.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 10.14.7 10.14.7 2025-12-04 ✓ corregido en la última versión
CVE-2025-64381 Booking Calendar [booking] < 10.14.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 10.14.8 10.14.8 2025-11-13 ✓ corregido en la última versión
CVE-2024-13821 Booking Calendar [booking] < 10.10.1 Autorización indebida Media 5,3 < 10.10.1 10.10.1 2025-02-11 ✓ corregido en la última versión
CVE-2024-13323 Booking Calendar [booking] < 10.9.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 10.9.3 10.9.3 2025-01-13 ✓ corregido en la última versión

CVE-2026-32358

The Booking Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.14.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-14982

The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposure in all versions up to, and including, 10.14.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view all booking records in the database, including personally identifiable information (PII) such as names, email addresses, phone numbers, physical addresses, payment status, booking costs, and booking hashes belonging to other users.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-14146

The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default (`booking_is_nonce_at_front_end` option is `'Off'` by default). When the `booking_is_show_popover_in_timeline_front_end` option is enabled (which is the default in demo installations and can be enabled by administrators), it is possible for unauthenticated attackers to extract sensitive booking data including customer names, email addresses, phone numbers, and booking details.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-14383

The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, and including, 10.14.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-12804

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-64381

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.14.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-13821

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-13323

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 34 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-10893 Booking Calendar [booking] < 10.6.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 10.6.5 10.6.5 2024-11-14 ✓ corregido en la última versión
CVE-2024-10027 Booking Calendar [booking] < 10.6.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 10.6.3 10.6.3 2024-10-17 ✓ corregido en la última versión
CVE-2024-9306 Booking Calendar [booking] < 10.6.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 10.6.1 10.6.1 2024-10-03 ✓ corregido en la última versión
CVE-2024-8274 Booking Calendar [booking] < 10.5.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 10.5.1 10.5.1 2024-08-29 ✓ corregido en la última versión
CVE-2024-6930 Booking Calendar [booking] < 10.2.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 10.2.2 10.2.2 2024-07-23 ✓ corregido en la última versión
CVE-2024-1207 Booking Calendar [booking] < 9.9.1 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Crítica 9,8 < 9.9.1 9.9.1 2024-02-07 ✓ corregido en la última versión
CVE-2023-51520 Booking Calendar [booking] < 9.7.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 9.7.4 9.7.4 2024-02-01 ✓ corregido en la última versión
Booking Calendar [booking] < 9.7.4 Desconocido < 9.7.4 9.7.4 2023-09-25 ✓ corregido en la última versión
CVE-2023-4620 Booking Calendar [booking] < 9.7.3.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 9.7.3.1 9.7.3.1 2023-09-11 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 2023-08-01 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 2023-07-14 ✓ corregido en la última versión
CVE-2023-23991 Booking Calendar [booking] < 9.4.3.1 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 7,6 < 9.4.3.1 9.4.3.1 2023-01-20 ✓ corregido en la última versión
CVE-2022-33177 Booking Calendar [booking] < 9.2.2 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 9.2.2 9.2.2 2022-09-06 ✓ corregido en la última versión
CVE-2022-1463 Booking Calendar [booking] < 9.1.1 Deserialización de datos no confiables Alta 8,8 < 9.1.1 9.1.1 2022-04-18 ✓ corregido en la última versión
CVE-2021-25040 Booking Calendar [booking] < 8.9.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 8.9.2 8.9.2 2021-12-06 ✓ corregido en la última versión
CVE-2018-20556 Booking Calendar [booking] < 8.4.5.15 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 8,8 < 8.4.5.15 8.4.5.15 2018-12-28 ✓ corregido en la última versión
CVE-2017-2150 Booking Calendar [booking] <= 7.0 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 5,3 < 7.0 7.0 2017-04-20 ✓ corregido en la última versión
CVE-2017-2151 Booking Calendar [booking] <= 7.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 7.1 7.1 2017-04-20 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 2016-08-01 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 2016-08-01 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 2016-08-01 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 2016-08-01 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 2016-08-01 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 2016-08-01 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 2016-07-14 ✓ corregido en la última versión
Booking Calendar [booking] < 4.1.6 Desconocido < 4.1.6 4.1.6 2014-08-01 ✓ corregido en la última versión
Booking Calendar [booking] < 4.1.6 Desconocido < 4.1.6 4.1.6 2014-08-01 ✓ corregido en la última versión
CVE-2025-4669 Booking Calendar [booking] < 10.11.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 10.11.2 10.11.2 0000-00-00 ✓ corregido en la última versión
CVE-2026-1431 Booking Calendar [booking] < 10.14.14 Media 5,3 < 10.14.14 10.14.14 0000-00-00 ✓ corregido en la última versión
CVE-2026-2230 Booking Calendar [booking] < 10.14.15 Desconocido < 10.14.15 10.14.15 0000-00-00 ✓ corregido en la última versión
Booking Calendar [booking] < 10.14.2 Media 6,4 < 10.14.2 10.14.2 0000-00-00 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 ✓ corregido en la última versión
Booking Calendar [booking] < 6.2.1 Desconocido < 6.2.1 6.2.1 ✓ corregido en la última versión
Booking Calendar [booking] < 4.1.6 Desconocido < 4.1.6 4.1.6 ✓ corregido en la última versión

CVE-2024-10893

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-10027

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-9306

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. In addition, site administrators have the option to grant lower-level users with access to manage the plugin's settings which may extend this vulnerability to those users.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-8274

The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-6930

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions up to, and including, 10.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-1207

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-51520

Update the WordPress Booking Calendar plugin to the latest available version (at least 9.7.4). Ngô Thiên An (ancorn_ from VNPT-VCI) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.7.4. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Booking Calendar [booking] < 9.7.4

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 9.7.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-4620

Update the WordPress Booking Calendar plugin to the latest available version (at least 9.7.3.1). Pablo Sanchez discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.7.3.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Booking Calendar [booking] < 6.2.1

Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.2.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Booking Calendar [booking] < 6.2.1

Update Booking Calendar Plugin to 6.2.1. Edwin Molenaar discovered and reported this SQL Injection vulnerability in WordPress Booking Calendar Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 6.2.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-23991

The Booking Calendar plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 9.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrative privileges, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-33177

The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.2.1. This is due to missing or incorrect nonce validation on the wpbc_translation_buttons_settings_section function. This makes it possible for unauthenticated attackers to update translation settings, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-1463

The plugin unserializes user data without being validated first, which could allow attackers to perform PHP object injection attack. If a timeline is published, unauthenticated attackers could perform such attack, otherwise any authenticated could. A suitable POP chain, from another plugin for example, would also be needed for a successful attack

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2021-25040

The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2018-20556

SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2017-2150

The WordPress plugin "Booking Calendar" provided by wpdevelop contains a directory traversal vulnerability (CWE-22). ASAI Ken reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

CVE-2017-2151

The WordPress plugin "Booking Calendar" provided by wpdevelop contains a stored cross-site scripting vulnerability (CWE-79). Satoshi Takagi of Cryptography Laboratory,Department of Information and Communication Engineering,Tokyo Denki University reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

Booking Calendar [booking] < 6.2.1

Reflected Cross-Site Scripting (XSS) vulnerability discovered by ethicalhack3r in WordPress Booking Calendar plugin (versions <= 6.2). Update the WordPress Booking Calendar plugin to the latest available version (at least 6.2.1).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Booking Calendar [booking] < 6.2.1

SQL Injection (SQLi) vulnerability discovered by ethicalhack3r in WordPress Booking Calendar plugin (versions <= 6.2). Update the WordPress Booking Calendar plugin to the latest available version (at least 6.2.1).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Booking Calendar [booking] < 6.2.1

The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation in the plugin's Import tab. This makes it possible for unauthenticated attackers to to inject arbitrary web scripts that execute in a victim's browser via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Booking Calendar [booking] < 6.2.1

The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2. This is due to missing or incorrect nonce validation on the wpdev_get_args_from_request_in_bk_listing function. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Booking Calendar [booking] < 6.2.1

The Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the booking ID field in versions up to, and including, 6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for Editor-level attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Booking Calendar [booking] < 6.2.1

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Booking Calendar [booking] < 6.2.1

Booking Calendar Plugin before 6.2 is prone to a SQL Injection vulnerability. The parameters are not sanitized properly in the wpdev_get_args_from_request_in_bk_listing() function from booking/lib/wpdev-bk-lib.php (line 709). It allows remote attackers to view data from the database by luring the target user into a malicious website. Update Booking Calendar Plugin to 6.2.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Booking Calendar [booking] < 4.1.6

Cross-Site Request Forgery (CSRF) vulnerability discovered by Dylan Irzi in WordPress Booking Calendar plugin (versions <= 4.1.5). Update the WordPress Booking Calendar plugin to the latest available version (at least 4.1.6).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Booking Calendar [booking] < 4.1.6

The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 4.1.6. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to make arbitrary calendar changes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-4669

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-1431

The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking information including customer names, phones and emails.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: euvd.enisa.europa.eu

CVE-2026-2230

The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, and booking permissions granted by an Administrator, to modify other users' plugin settings, such as booking calendar display options, which can disrupt the booking calendar functionality for the targeted user.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Booking Calendar [booking] < 10.14.2

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 10.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Booking Calendar [booking] < 6.2.1

The Booking Calendar WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Booking Calendar [booking] < 6.2.1

The Booking Calendar WordPress plugin was affected by a SQL Injection security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Booking Calendar [booking] < 4.1.6

The Booking Calendar WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Booking actualizado — 11.4.2 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.