Medium 5.3
2026-04-24< 1.2.64
CVE-2026-6810
Minimum safe version
1.2.64
Update to 1.2.64 or later to address 15 fixable vulnerabilities
CVE-2026-6810
CVE-2025-13318
CVE-2025-48231
CVE-2025-24723
CVE-2023-36384
CVE-2023-25037
Booking Calendar Contact Form <= 1.0.23 - Shortcode SQL Injection
WordPress Booking Calendar Contact Form Plugin 1.0.2 - Multiple vulnerabilities
WordPress Booking Calendar Contact Form Plugin 1.1.23 - Unauthenticated SQL Injection
WordPress Booking Calendar Contact Form Plugin 1.1.23 - Shortcode SQL Injection
WordPress Booking Calendar Contact Form Plugin 1.1.24 - Multiple Vulnerabilities
WordPress Booking Calendar Contact Form Plugin 1.1.24 - Addslashes SQL Injection
WordPress Booking Calendar Contact Form Plugin 1.0.23 - Multiple Vulnerabilities
CVE-2016-10909
CVE-2016-10908