PLUGIN SECURITY
Is Booked safe?
WP Booking Calendar plugin for full-day bookings, time-slot appointments, rentals & events. Accept bookings and inquiries with flexible contact forms
What this plugin does
- Slug:
booked - Author: wpdevelop
- 40000+ active installs
- 94/100 rating (655 reviews on wordpress.org)
- 5265202 all-time downloads
- On WordPress.org since 2009-08-15
appointment bookingavailability calendarbooking calendarbooking formonline booking
Maintenance status
- Latest known version: 7.4.2
- Last updated: 2026-08-31 7:56pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.6+
Known vulnerabilities
4 known CVEs on file for Booked. Reported between 2020 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-57747 | Booked [booked] <= 3.0.0 (unfixed) | Cross-Site Request Forgery (CSRF) | Medium 6.5 | < 3.0.0 | 3.0.0 | 2026-07-02 | ✓ fixed in latest |
| CVE-2026-57746 | Booked [booked] <= 3.0.0 (unfixed) | Missing Authorization | High 7.1 | < 3.0.0 | 3.0.0 | 2026-07-02 | ✓ fixed in latest |
| — | Booked [booked] <= 3.0.0 (unfixed) | Authentication Bypass Using an Alternate Path or Channel | Medium 6.7 | < 3.0.0 | 3.0.0 | 2026-01-29 | ✓ fixed in latest |
| CVE-2022-36399 | Booked [booked] < 2.4.4 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 2.4.4 | 2.4.4 | 2023-06-27 | ✓ fixed in latest |
| — | Booked [booked] < 2.2.6 | — | Unknown | < 2.2.6 | 2.2.6 | 2020-02-29 | ✓ fixed in latest |
| — | Booked [booked] < 2.2.6 | — | Unknown | < 2.2.6 | 2.2.6 | 2020-02-28 | ✓ fixed in latest |
| — | Booked [booked] < 2.2.6 | — | Unknown | < 2.2.6 | 2.2.6 | — | ✓ fixed in latest |
| — | Booked < 2.2.6 - Broken Authentication to Export Users Data in CSV | — | Unknown | < 2.2.6 | 2.2.6 | — | ✓ fixed in latest |
+ 1 more known vulnerability
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-22341 | Booked <= 3.0.0 - Authentication Bypass | — | Unknown | not specified | no fix on file | — | — |
How to fix it
Keep Booked updated — 7.4.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — 100000+ active installs — 98/100 (99) — max PHP 8.4
- Online Scheduling and Appointment Booking System – Bookly — 60000+ active installs — 88/100 (576) — max PHP <8.0
- Simply Schedule Appointments — 50000+ active installs — 100/100 (155) — max PHP 8.4
- Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution — 20000+ active installs — 94/100 (43)
- WP Simple Booking Calendar — 20000+ active installs — 96/100 (227)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.