VYPR

Booking Calendar

by WordPress

Source repositories

CVEs (32)

  • CVE-2025-14146MedJan 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default…

  • CVE-2024-13821MedFeb 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being…

  • CVE-2024-12077MedJan 7, 2025
    risk 0.33cvss 6.1epss 0.00

    The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘calendar_id’ parameter in all versions up to, and including, 3.2.19 and 11.2.19 respectively, due to insufficient input sanitization and output…

  • CVE-2024-8274MedAug 30, 2024
    risk 0.33cvss 6.1epss 0.01

    The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-10893MedDec 3, 2024
    risk 0.31cvss 4.8epss 0.00

    The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2024-10027MedNov 7, 2024
    risk 0.31cvss 4.8epss 0.00

    The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for…

  • CVE-2018-5672MedJan 13, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter.

  • CVE-2018-5671MedJan 13, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter.

  • CVE-2018-5670MedJan 13, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][] parameter.

  • CVE-2025-14982MedJan 16, 2026
    risk 0.28cvss 4.3epss 0.00

    The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposure in all versions up to, and including, 10.14.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view all…

  • CVE-2026-2230MedFeb 18, 2026
    risk 0.21cvss 4.3epss 0.00

    The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation on a user controlled key. This makes it possible for authenticated attackers,…

  • CVE-2026-59558HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

Page 2 of 2