Resources /
WordPress Plugins /
Booked
PLUGIN SECURITY
Is Booked safe?
Known vulnerabilities, PHP compatibility and safer alternatives for the Booked WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
Maintenance status
Known vulnerabilities
3 known CVEs on file for Booked.
Reported between 2020 and 2026.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-57747
|
Booked [booked] <= 3.0.0 (unfixed) |
Cross-Site Request Forgery (CSRF) |
Medium
6.5
|
< 3.0.0
|
3.0.0 |
2026-07-02 |
—
|
|
CVE-2026-57746
|
Booked [booked] <= 3.0.0 (unfixed) |
Missing Authorization |
High
7.1
|
< 3.0.0
|
3.0.0 |
2026-07-02 |
—
|
|
—
|
Booked [booked] <= 3.0.0 (unfixed) |
Authentication Bypass Using an Alternate Path or Channel |
Medium
6.7
|
< 3.0.0
|
3.0.0 |
2026-01-29 |
—
|
|
CVE-2022-36399
|
Booked [booked] < 2.4.4 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
5.3
|
< 2.4.4
|
2.4.4 |
2023-06-27 |
—
|
|
—
|
Booked [booked] < 2.2.6 |
— |
Unknown
|
< 2.2.6
|
2.2.6 |
2020-02-29 |
—
|
|
—
|
Booked [booked] < 2.2.6 |
— |
Unknown
|
< 2.2.6
|
2.2.6 |
2020-02-28 |
—
|
|
—
|
Booked [booked] < 2.2.6 |
— |
Unknown
|
< 2.2.6
|
2.2.6 |
— |
—
|
CVE-2026-57747
The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
CVE-2026-57746
The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
Source:
Wordfence
Booked [booked] <= 3.0.0 (unfixed)
The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Custom-level access and above, to bypass authentication and access other user's accounts.
Source:
Wordfence
CVE-2022-36399
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This issue affects Booked - Appointment Booking for WordPress | Calendars: from n/a before 2.4.4.
Source:
CVE.org
Booked [booked] < 2.2.6
The Booked plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions hooked via AJAX actions in versions up to, and including, 2.2.5. This makes it possible for authenticated attackers with subscriber-level permissions and above to execute several unauthorized actions.
Source:
Wordfence
Booked [booked] < 2.2.6
Broken Authentication vulnerability leading to Sensitive Information disclosure discovered by Noman Riffat in WordPress Booked premium plugin (versions <= 2.2.5).
Source:
Patchstack
Booked [booked] < 2.2.6
The plugin allows users to Book Appointment by providing their PII such as Email, Name, Phone Number and Personal Message. The vulnerability allows anyone to Dump all records of users and their appointment details in CSV as an unauthenticated user.
The user also gets registered as a WP User after submitting appointment which introduces more vulnerabilities i.e. a subscriber can approve, delete or modify any appointment and inject Stored XSS.
Edit (WPScanTeam):
February 7th, 2020 - Report Received & Envato Contacted
February 7th, 2020 - Envato Investigating
February 29th, 2020 - v2.2.6 released, fixing the issues
Source:
WPScan
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.