PLUGIN SECURITY

Is Booking safe?

WP Booking Calendar plugin for full-day bookings, time-slot appointments, rentals & events. Accept bookings and inquiries with flexible contact forms

What this plugin does

  • Slug: booking
  • Author: wpdevelop
  • 40000+ active installs
  • 94/100 rating (653 reviews on wordpress.org)
  • 5238537 all-time downloads
  • On WordPress.org since 2009-08-15

appointment bookingavailability calendarbooking calendarbooking formonline booking

Maintenance status

  • Latest known version: 11.5
  • Last updated: 2026-08-23 6:09pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 5.6+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

28 known CVEs on file for Booking.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-32358 Booking Calendar [booking] < 10.14.16 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 10.14.16 10.14.16 2026-02-14 ✓ fixed in latest
CVE-2025-14982 Booking Calendar [booking] < 10.14.12 Missing Authorization Medium 4.3 < 10.14.12 10.14.12 2026-01-15 ✓ fixed in latest
CVE-2025-14146 Booking Calendar [booking] < 10.14.11 Missing Authorization Medium 5.3 < 10.14.11 10.14.11 2026-01-08 ✓ fixed in latest
CVE-2025-14383 Booking Calendar [booking] < 10.14.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 10.14.9 10.14.9 2025-12-15 ✓ fixed in latest
CVE-2025-12804 Booking Calendar [booking] < 10.14.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 10.14.7 10.14.7 2025-12-04 ✓ fixed in latest
CVE-2025-64381 Booking Calendar [booking] < 10.14.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 10.14.8 10.14.8 2025-11-13 ✓ fixed in latest
CVE-2024-13821 Booking Calendar [booking] < 10.10.1 Improper Authorization Medium 5.3 < 10.10.1 10.10.1 2025-02-11 ✓ fixed in latest
CVE-2024-13323 Booking Calendar [booking] < 10.9.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 10.9.3 10.9.3 2025-01-13 ✓ fixed in latest
+ 43 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10893 Booking Calendar [booking] < 10.6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 10.6.5 10.6.5 2024-11-14 ✓ fixed in latest
CVE-2024-10027 Booking Calendar [booking] < 10.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 10.6.3 10.6.3 2024-10-17 ✓ fixed in latest
CVE-2024-9306 Booking Calendar [booking] < 10.6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 10.6.1 10.6.1 2024-10-03 ✓ fixed in latest
CVE-2024-8274 Booking Calendar [booking] < 10.5.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 10.5.1 10.5.1 2024-08-29 ✓ fixed in latest
CVE-2024-6930 Booking Calendar [booking] < 10.2.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 10.2.2 10.2.2 2024-07-23 ✓ fixed in latest
CVE-2024-1207 Booking Calendar [booking] < 9.9.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 9.9.1 9.9.1 2024-02-07 ✓ fixed in latest
CVE-2023-51520 Booking Calendar [booking] < 9.7.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 9.7.4 9.7.4 2023-09-25 ✓ fixed in latest
CVE-2023-4620 Booking Calendar [booking] < 9.7.3.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 9.7.3.1 9.7.3.1 2023-09-11 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 2023-08-01 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 2023-07-14 ✓ fixed in latest
CVE-2023-23991 Booking Calendar [booking] < 9.4.3.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 9.4.3.1 9.4.3.1 2023-01-20 ✓ fixed in latest
CVE-2022-33177 Booking Calendar [booking] < 9.2.2 Cross-Site Request Forgery (CSRF) Medium 5.4 < 9.2.2 9.2.2 2022-09-06 ✓ fixed in latest
CVE-2022-1463 Booking Calendar [booking] < 9.1.1 Deserialization of Untrusted Data High 8.8 < 9.1.1 9.1.1 2022-04-18 ✓ fixed in latest
CVE-2021-25040 Booking Calendar [booking] < 8.9.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.9.2 8.9.2 2021-12-06 ✓ fixed in latest
CVE-2018-20556 Booking Calendar [booking] < 8.4.5.15 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 8.4.5.15 8.4.5.15 2018-12-28 ✓ fixed in latest
CVE-2017-2150 Booking Calendar [booking] <= 7.0 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 5.3 < 7.0 7.0 2017-04-20 ✓ fixed in latest
CVE-2017-2151 Booking Calendar [booking] <= 7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 7.1 7.1 2017-04-20 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 2016-08-01 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 2016-08-01 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 2016-08-01 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 2016-08-01 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 2016-08-01 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 2016-08-01 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 2016-07-14 ✓ fixed in latest
Booking Calendar [booking] < 4.1.6 Unknown < 4.1.6 4.1.6 2014-08-01 ✓ fixed in latest
Booking Calendar [booking] < 4.1.6 Unknown < 4.1.6 4.1.6 2014-08-01 ✓ fixed in latest
Booking Calendar [booking] < 10.11.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 10.11.2 10.11.2 0000-00-00 ✓ fixed in latest
Booking Calendar [booking] < 10.14.14 Medium 5.3 < 10.14.14 10.14.14 0000-00-00 ✓ fixed in latest
Booking Calendar [booking] < 10.14.15 Unknown < 10.14.15 10.14.15 0000-00-00 ✓ fixed in latest
Booking Calendar [booking] < 10.14.2 Medium 6.4 < 10.14.2 10.14.2 0000-00-00 ✓ fixed in latest
Booking Calendar [booking] < 11.4.3 Unknown < 11.4.3 11.4.3 0000-00-00 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 ✓ fixed in latest
Booking Calendar [booking] < 6.2.1 Unknown < 6.2.1 6.2.1 ✓ fixed in latest
Booking Calendar [booking] < 4.1.6 Unknown < 4.1.6 4.1.6 ✓ fixed in latest
Booking Calendar <= 4.1.5 - Cross-Site Request Forgery (CSRF) Unknown < 4.1.6 4.1.6 ✓ fixed in latest
Booking Calendar <= 6.2 - Reflected Cross-Site Scripting (XSS) Unknown < 6.2.1 6.2.1 ✓ fixed in latest
Booking Calendar <= 6.2 - SQL Injection Unknown < 6.2.1 6.2.1 ✓ fixed in latest
Booking Calendar < 9.7.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode Unknown < 9.7.4 9.7.4 ✓ fixed in latest
CVE-2025-4669 Booking Calendar < 10.11.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode Unknown < 10.11.2 10.11.2 ✓ fixed in latest
CVE-2025-9346 Booking Calendar < 10.14.2 - Authenticated (Contributor+) Stored Cross-Site Scripting Unknown < 10.14.2 10.14.2 ✓ fixed in latest
CVE-2026-1431 Booking Calendar < 10.14.14 - Missing Authorization to Unauthenticated Booking Details Exposure Unknown < 10.14.14 10.14.14 ✓ fixed in latest
CVE-2026-2230 Booking Calendar < 10.14.15 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification Unknown < 10.14.15 10.14.15 ✓ fixed in latest
CVE-2026-59558 Booking Calendar < 11.4.3 - Unauthenticated Stored Cross-Site Scripting Unknown < 11.4.3 11.4.3 ✓ fixed in latest

How to fix it

Keep Booking updated — 11.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.