WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Booked safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Booked WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: booked

Maintenance status

Known vulnerabilities

3 known CVEs on file for Booked. Reported between 2020 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57747 Booked [booked] <= 3.0.0 (unfixed) Cross-Site Request Forgery (CSRF) Medium 6.5 < 3.0.0 3.0.0 2026-07-02
CVE-2026-57746 Booked [booked] <= 3.0.0 (unfixed) Missing Authorization High 7.1 < 3.0.0 3.0.0 2026-07-02
Booked [booked] <= 3.0.0 (unfixed) Authentication Bypass Using an Alternate Path or Channel Medium 6.7 < 3.0.0 3.0.0 2026-01-29
CVE-2022-36399 Booked [booked] < 2.4.4 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 2.4.4 2.4.4 2023-06-27
Booked [booked] < 2.2.6 Unknown < 2.2.6 2.2.6 2020-02-29
Booked [booked] < 2.2.6 Unknown < 2.2.6 2.2.6 2020-02-28
Booked [booked] < 2.2.6 Unknown < 2.2.6 2.2.6

CVE-2026-57747

The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

CVE-2026-57746

The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

Source: Wordfence

Booked [booked] <= 3.0.0 (unfixed)

The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Custom-level access and above, to bypass authentication and access other user's accounts.

Source: Wordfence

CVE-2022-36399

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This issue affects Booked - Appointment Booking for WordPress | Calendars: from n/a before 2.4.4.

Source: CVE.org

Booked [booked] < 2.2.6

The Booked plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions hooked via AJAX actions in versions up to, and including, 2.2.5. This makes it possible for authenticated attackers with subscriber-level permissions and above to execute several unauthorized actions.

Source: Wordfence

Booked [booked] < 2.2.6

Broken Authentication vulnerability leading to Sensitive Information disclosure discovered by Noman Riffat in WordPress Booked premium plugin (versions <= 2.2.5).

Source: Patchstack

Booked [booked] < 2.2.6

The plugin allows users to Book Appointment by providing their PII such as Email, Name, Phone Number and Personal Message. The vulnerability allows anyone to Dump all records of users and their appointment details in CSV as an unauthenticated user. The user also gets registered as a WP User after submitting appointment which introduces more vulnerabilities i.e. a subscriber can approve, delete or modify any appointment and inject Stored XSS. Edit (WPScanTeam): February 7th, 2020 - Report Received & Envato Contacted February 7th, 2020 - Envato Investigating February 29th, 2020 - v2.2.6 released, fixing the issues

Source: WPScan

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.