PLUGIN SECURITY

Is Booked safe?

WP Booking Calendar plugin for full-day bookings, time-slot appointments, rentals & events. Accept bookings and inquiries with flexible contact forms

What this plugin does

  • Slug: booked
  • Author: wpdevelop
  • 40000+ active installs
  • 94/100 rating (655 reviews on wordpress.org)
  • 5265202 all-time downloads
  • On WordPress.org since 2009-08-15

appointment bookingavailability calendarbooking calendarbooking formonline booking

Maintenance status

  • Latest known version: 7.4.2
  • Last updated: 2026-08-31 7:56pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 5.6+

Known vulnerabilities

4 known CVEs on file for Booked. Reported between 2020 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57747 Booked [booked] <= 3.0.0 (unfixed) Cross-Site Request Forgery (CSRF) Medium 6.5 < 3.0.0 3.0.0 2026-07-02 ✓ fixed in latest
CVE-2026-57746 Booked [booked] <= 3.0.0 (unfixed) Missing Authorization High 7.1 < 3.0.0 3.0.0 2026-07-02 ✓ fixed in latest
Booked [booked] <= 3.0.0 (unfixed) Authentication Bypass Using an Alternate Path or Channel Medium 6.7 < 3.0.0 3.0.0 2026-01-29 ✓ fixed in latest
CVE-2022-36399 Booked [booked] < 2.4.4 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 2.4.4 2.4.4 2023-06-27 ✓ fixed in latest
Booked [booked] < 2.2.6 Unknown < 2.2.6 2.2.6 2020-02-29 ✓ fixed in latest
Booked [booked] < 2.2.6 Unknown < 2.2.6 2.2.6 2020-02-28 ✓ fixed in latest
Booked [booked] < 2.2.6 Unknown < 2.2.6 2.2.6 ✓ fixed in latest
Booked < 2.2.6 - Broken Authentication to Export Users Data in CSV Unknown < 2.2.6 2.2.6 ✓ fixed in latest
+ 1 more known vulnerability
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-22341 Booked <= 3.0.0 - Authentication Bypass Unknown not specified no fix on file

How to fix it

Keep Booked updated — 7.4.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.