CVE-2026-25435
Booking calendar, Appointment Booking System
Minimum safe version
3.2.31
Update to 3.2.31 or later to address 21 fixable vulnerabilities
Booking calendar, Appointment Booking System <= 3.2.30 - Missing Authorization
Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'
CVE-2024-12077
CVE-2024-10856
CVE-2024-9504
Booking Calendar WpDevArt < 3.2.12 - Admin+ SQLi
Booking calendar, Appointment Booking System < 3.2.9 - Multiple Authenticated(Editor+) SQL Injection
Booking Calendar WpDevArt <= 3.2.11 - Authenticated (Admin+) SQL Injection
Booking calendar, Appointment Booking System <= 3.2.8 - Multiple Authenticated(Editor+) SQL Injection
CVE-2022-47428
CVE-2023-24373
CVE-2022-47438
CVE-2023-24407
CVE-2023-24388
CVE-2022-3982
WordPress Booking calendar plugin <=2.1.7 - Multiple Cross-Site Scripting (XSS) vulnerabilities
WordPress Booking calendar plugin <=2.1.7 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2018-5672
CVE-2018-5671
CVE-2018-5670
CVE-2018-10363