Plugin Vulnerability Hub
Plugin 19 known issues Latest disclosed Mar 18, 2026

Booking calendar, Appointment Booking System Vulnerabilities

Review known vulnerability records for the WordPress plugin Booking calendar, Appointment Booking System (`booking-calendar`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-25435 and CVE-2025-67574, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
19
High or Critical
8
Patch Coverage
100%
Last Updated
Mar 26, 2026
Priority CVE Quick Links

Fast paths into Booking calendar, Appointment Booking System CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
16
CVE-2022-3982 Critical 3.2.2
CVE-2022-3982 Booking calendar, Appointment Booking System Remote Code Execution

Booking calendar, Appointment Booking System <= 3.2.1 - Unauthenticated Arbitrary File Upload

CVE-2018-5673 High 2.1.8
CVE-2018-5673 Booking calendar, Appointment Booking System Cross-Site Request Forgery

Booking calendar, Appointment Booking System <= 2.1.7 - Cross-Site Request Forgery

CVE-2018-10363 High 2.2.3
CVE-2018-10363 Booking calendar, Appointment Booking System Vulnerability

Booking calendar, Appointment Booking System < 2.2.3 - Unauthenticated Parameter Manipulation

CVE-2026-25435 High No patch listed
CVE-2026-25435 Booking calendar, Appointment Booking System Stored Cross-Site Scripting

Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored Cross-Site Scripting

CVE-2024-9504 High 3.2.16
CVE-2024-9504 Booking calendar, Appointment Booking System File Upload

Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

CVE-2022-47428 High 3.2.7
CVE-2022-47428 Booking calendar, Appointment Booking System SQL Injection

Booking calendar, Appointment Booking System <= 3.2.6 - Authenticated (Administrator+) SQL Injection via *_selected

CVE-2024-10856 Medium 3.2.20
CVE-2024-10856 Booking calendar, Appointment Booking System SQL Injection

Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection

CVE-2024-12077 Medium 3.2.20
CVE-2024-12077 Booking calendar, Appointment Booking System Cross-Site Scripting

Booking Calendar and Booking Calendar Pro <= Multiple Versions - Reflected Cross-Site Scripting via 'calendar_id'

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Booking calendar, Appointment Booking System so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
19 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 7 high severity findings.
Recent CVEs
CVE-2026-25435 and CVE-2025-67574
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Booking calendar, Appointment Booking System

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: No CVE-2026-25435
CVE-2026-25435: Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored Cross-Site Scripting

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...

Published
Mar 18, 2026
Patched Release
Not published
Affected Versions
Versions up to 3.2.36
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: Yes CVE-2025-67574
CVE-2025-67574: Booking calendar, Appointment Booking System <= 3.2.30 - Missing Authorization

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.30. This makes it possible for unauthenticated attackers to perform an unauthorized...

Published
Dec 15, 2025
Patched Release
3.2.31
Affected Versions
Versions up to 3.2.30
Next Step
Update to 3.2.31 or newer if supported.
Plugin Medium Patched: Yes
Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpdevart_id’ parameter in all versions up to, and including, 3.2.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat...

Published
Jul 01, 2025
Patched Release
3.2.18
Affected Versions
Versions up to 3.2.17
Next Step
Update to 3.2.18 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-12077
CVE-2024-12077: Booking Calendar and Booking Calendar Pro <= Multiple Versions - Reflected Cross-Site Scripting via 'calendar_id'

The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘calendar_id’ parameter in all versions up to, and including, 3.2.19 and 11.2.19 respectively, due to insufficient input sanitization and output escaping....

Published
Jan 06, 2025
Patched Release
3.2.20
Affected Versions
Versions up to 3.2.19
Next Step
Update to 3.2.20 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10856
CVE-2024-10856: Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection

The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpdevart_booking_calendar” shortcode in versions up to, and including, 3.2.19 due to insufficient escaping on the user-supplied parameter and lack of sufficient pr...

Published
Dec 23, 2024
Patched Release
3.2.20
Affected Versions
Versions up to 3.2.19
Next Step
Update to 3.2.20 or newer if supported.
Plugin High Patched: Yes CVE-2024-9504
CVE-2024-9504: Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica...

Published
Nov 25, 2024
Patched Release
3.2.16
Affected Versions
Versions up to 3.2.15
Next Step
Update to 3.2.16 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-24407
CVE-2023-24407: Booking calendar, Appointment Booking System <= 3.2.3 - Missing Authorization

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with Editor-level access and...

Published
Jan 27, 2024
Patched Release
3.2.4
Affected Versions
Versions up to 3.2.3
Next Step
Update to 3.2.4 or newer if supported.
Plugin High Patched: Yes
Booking Calendar WpDevArt <= 3.2.11 - Authenticated (Admin+) SQL Injection

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to SQL Injection via the '$email_address' variable in all versions up to, and including, 3.2.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on th...

Published
Oct 29, 2023
Patched Release
3.2.12
Affected Versions
Versions up to 3.2.11
Next Step
Update to 3.2.12 or newer if supported.
Plugin High Patched: Yes
Booking calendar, Appointment Booking System <= 3.2.8 - Multiple Authenticated(Editor+) SQL Injection

The Booking calendar plugin for WordPress is vulnerable to SQL Injection via the search functionality on multiple administrative pages in versions up to, and including, 3.2.8 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the ex...

Published
Sep 12, 2023
Patched Release
3.2.9
Affected Versions
Versions before 3.2.9
Next Step
Update to 3.2.9 or newer if supported.
Plugin High Patched: Yes CVE-2022-47428
CVE-2022-47428: Booking calendar, Appointment Booking System <= 3.2.6 - Authenticated (Administrator+) SQL Injection via *_selected

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to generic SQL Injection via the multiple *_selected functions in versions up to, and including, 3.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio...

Published
Apr 19, 2023
Patched Release
3.2.7
Affected Versions
Versions up to 3.2.6
Next Step
Update to 3.2.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-24373
CVE-2023-24373: Booking calendar, Appointment Booking System <= 3.2.3 - Unauthenticated Bypass Vulnerability

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to a bypass in all versions up to, and including, 3.2.3. This makes it possible for unauthenticated attackers to bypass controls. It is unclear from the original source of this vulnerability what...

Published
Jan 27, 2023
Patched Release
3.2.4
Affected Versions
Versions up to 3.2.3
Next Step
Update to 3.2.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-47438
CVE-2022-47438: Booking calendar, Appointment Booking System <= 3.2.3 - Authenticated (Editor+) Stored Cross-Site Scripting

The Booking calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level perm...

Published
Jan 27, 2023
Patched Release
3.2.4
Affected Versions
Versions up to 3.2.3
Next Step
Update to 3.2.4 or newer if supported.