Medium 6.7 Unfixed
2026-02-20≤ 3.0.0
WordPress Booked plugin <= 3.0.0 - Account Takeover vulnerability
Minimum safe version
2.4.4
Update to 2.4.4 or later to address 4 fixable vulnerabilities
WordPress Booked plugin <= 3.0.0 - Account Takeover vulnerability
CVE-2022-36399
Booked <= 2.2.5 - Missing Authorization on AJAX Actions
Booked < 2.2.6 - Broken Authentication to Export Users Data in CSV
WordPress Booked premium plugin <= 2.2.5 - Broken Authentication vulnerability leading to Sensitive Information disclosure