PLUGIN SECURITY
Is Booking safe?
WP Booking Calendar plugin for full-day bookings, time-slot appointments, rentals & events. Accept bookings and inquiries with flexible contact forms
What this plugin does
- Slug:
booking - Author: wpdevelop
- 40000+ active installs
- 94/100 rating (653 reviews on wordpress.org)
- 5238537 all-time downloads
- On WordPress.org since 2009-08-15
appointment bookingavailability calendarbooking calendarbooking formonline booking
Maintenance status
- Latest known version: 11.5
- Last updated: 2026-08-23 6:09pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 5.6+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
28 known CVEs on file for Booking.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-32358 | Booking Calendar [booking] < 10.14.16 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.6 | < 10.14.16 | 10.14.16 | 2026-02-14 | ✓ fixed in latest |
| CVE-2025-14982 | Booking Calendar [booking] < 10.14.12 | Missing Authorization | Medium 4.3 | < 10.14.12 | 10.14.12 | 2026-01-15 | ✓ fixed in latest |
| CVE-2025-14146 | Booking Calendar [booking] < 10.14.11 | Missing Authorization | Medium 5.3 | < 10.14.11 | 10.14.11 | 2026-01-08 | ✓ fixed in latest |
| CVE-2025-14383 | Booking Calendar [booking] < 10.14.9 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 10.14.9 | 10.14.9 | 2025-12-15 | ✓ fixed in latest |
| CVE-2025-12804 | Booking Calendar [booking] < 10.14.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 10.14.7 | 10.14.7 | 2025-12-04 | ✓ fixed in latest |
| CVE-2025-64381 | Booking Calendar [booking] < 10.14.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 10.14.8 | 10.14.8 | 2025-11-13 | ✓ fixed in latest |
| CVE-2024-13821 | Booking Calendar [booking] < 10.10.1 | Improper Authorization | Medium 5.3 | < 10.10.1 | 10.10.1 | 2025-02-11 | ✓ fixed in latest |
| CVE-2024-13323 | Booking Calendar [booking] < 10.9.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 10.9.3 | 10.9.3 | 2025-01-13 | ✓ fixed in latest |
+ 43 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-10893 | Booking Calendar [booking] < 10.6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 10.6.5 | 10.6.5 | 2024-11-14 | ✓ fixed in latest |
| CVE-2024-10027 | Booking Calendar [booking] < 10.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 10.6.3 | 10.6.3 | 2024-10-17 | ✓ fixed in latest |
| CVE-2024-9306 | Booking Calendar [booking] < 10.6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 10.6.1 | 10.6.1 | 2024-10-03 | ✓ fixed in latest |
| CVE-2024-8274 | Booking Calendar [booking] < 10.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 10.5.1 | 10.5.1 | 2024-08-29 | ✓ fixed in latest |
| CVE-2024-6930 | Booking Calendar [booking] < 10.2.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 10.2.2 | 10.2.2 | 2024-07-23 | ✓ fixed in latest |
| CVE-2024-1207 | Booking Calendar [booking] < 9.9.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 9.9.1 | 9.9.1 | 2024-02-07 | ✓ fixed in latest |
| CVE-2023-51520 | Booking Calendar [booking] < 9.7.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 9.7.4 | 9.7.4 | 2023-09-25 | ✓ fixed in latest |
| CVE-2023-4620 | Booking Calendar [booking] < 9.7.3.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 9.7.3.1 | 9.7.3.1 | 2023-09-11 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2023-08-01 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2023-07-14 | ✓ fixed in latest |
| CVE-2023-23991 | Booking Calendar [booking] < 9.4.3.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.6 | < 9.4.3.1 | 9.4.3.1 | 2023-01-20 | ✓ fixed in latest |
| CVE-2022-33177 | Booking Calendar [booking] < 9.2.2 | Cross-Site Request Forgery (CSRF) | Medium 5.4 | < 9.2.2 | 9.2.2 | 2022-09-06 | ✓ fixed in latest |
| CVE-2022-1463 | Booking Calendar [booking] < 9.1.1 | Deserialization of Untrusted Data | High 8.8 | < 9.1.1 | 9.1.1 | 2022-04-18 | ✓ fixed in latest |
| CVE-2021-25040 | Booking Calendar [booking] < 8.9.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 8.9.2 | 8.9.2 | 2021-12-06 | ✓ fixed in latest |
| CVE-2018-20556 | Booking Calendar [booking] < 8.4.5.15 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 8.4.5.15 | 8.4.5.15 | 2018-12-28 | ✓ fixed in latest |
| CVE-2017-2150 | Booking Calendar [booking] <= 7.0 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 5.3 | < 7.0 | 7.0 | 2017-04-20 | ✓ fixed in latest |
| CVE-2017-2151 | Booking Calendar [booking] <= 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 7.1 | 7.1 | 2017-04-20 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2016-08-01 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2016-08-01 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2016-08-01 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2016-08-01 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2016-08-01 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2016-08-01 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | 2016-07-14 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 4.1.6 | — | Unknown | < 4.1.6 | 4.1.6 | 2014-08-01 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 4.1.6 | — | Unknown | < 4.1.6 | 4.1.6 | 2014-08-01 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 10.11.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 10.11.2 | 10.11.2 | 0000-00-00 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 10.14.14 | — | Medium 5.3 | < 10.14.14 | 10.14.14 | 0000-00-00 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 10.14.15 | — | Unknown | < 10.14.15 | 10.14.15 | 0000-00-00 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 10.14.2 | — | Medium 6.4 | < 10.14.2 | 10.14.2 | 0000-00-00 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 11.4.3 | — | Unknown | < 11.4.3 | 11.4.3 | 0000-00-00 | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | — | ✓ fixed in latest |
| — | Booking Calendar [booking] < 6.2.1 | — | Unknown | < 6.2.1 | 6.2.1 | — | ✓ fixed in latest |
| — | Booking Calendar [booking] < 4.1.6 | — | Unknown | < 4.1.6 | 4.1.6 | — | ✓ fixed in latest |
| — | Booking Calendar <= 4.1.5 - Cross-Site Request Forgery (CSRF) | — | Unknown | < 4.1.6 | 4.1.6 | — | ✓ fixed in latest |
| — | Booking Calendar <= 6.2 - Reflected Cross-Site Scripting (XSS) | — | Unknown | < 6.2.1 | 6.2.1 | — | ✓ fixed in latest |
| — | Booking Calendar <= 6.2 - SQL Injection | — | Unknown | < 6.2.1 | 6.2.1 | — | ✓ fixed in latest |
| — | Booking Calendar < 9.7.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode | — | Unknown | < 9.7.4 | 9.7.4 | — | ✓ fixed in latest |
| CVE-2025-4669 | Booking Calendar < 10.11.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode | — | Unknown | < 10.11.2 | 10.11.2 | — | ✓ fixed in latest |
| CVE-2025-9346 | Booking Calendar < 10.14.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 10.14.2 | 10.14.2 | — | ✓ fixed in latest |
| CVE-2026-1431 | Booking Calendar < 10.14.14 - Missing Authorization to Unauthenticated Booking Details Exposure | — | Unknown | < 10.14.14 | 10.14.14 | — | ✓ fixed in latest |
| CVE-2026-2230 | Booking Calendar < 10.14.15 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification | — | Unknown | < 10.14.15 | 10.14.15 | — | ✓ fixed in latest |
| CVE-2026-59558 | Booking Calendar < 11.4.3 - Unauthenticated Stored Cross-Site Scripting | — | Unknown | < 11.4.3 | 11.4.3 | — | ✓ fixed in latest |
How to fix it
Keep Booking updated — 11.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — 100000+ active installs — 98/100 (99) — max PHP 8.4
- Online Scheduling and Appointment Booking System – Bookly — 60000+ active installs — 88/100 (575) — max PHP <8.0
- Simply Schedule Appointments — 50000+ active installs — 100/100 (155) — max PHP 8.4
- Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution — 20000+ active installs — 94/100 (43)
- WP Simple Booking Calendar — 20000+ active installs — 96/100 (227)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.