Booking Calendar <= 10.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Booking Calendar
Minimum safe version
10.14.16
Update to 10.14.16 or later to address 40 fixable vulnerabilities
Booking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification
Booking Calendar <= 10.14.13 - Missing Authorization to Unauthenticated Booking Details Exposure
CVE-2026-32358
CVE-2025-14982
CVE-2025-14146
CVE-2025-14383
CVE-2025-12804
CVE-2025-64381
Booking Calendar <= 10.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode
CVE-2024-13821
CVE-2024-13323
CVE-2024-10893
CVE-2024-10027
CVE-2024-9306
CVE-2024-8274
CVE-2024-6930
CVE-2024-1207
WordPress Booking Calendar Plugin < 9.7.4 is vulnerable to Cross Site Scripting (XSS)
Booking Calendar <= 9.7.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
WordPress Booking Calendar Plugin <= 9.7.3 is vulnerable to Cross Site Scripting (XSS)
WordPress Booking Calendar Plugin <= 6.2 is vulnerable to Cross Site Scripting (XSS)
WordPress Booking Calendar Plugin <= 6.2 is vulnerable to SQL Injection
WordPress Booking Calendar Plugin 6.2 - SQL Injection
WordPress Booking Calendar Plugin <= 6.2 - Reflected Cross Site Scripting
CVE-2023-23991
Booking Calendar < 4.1.6 - Cross-Site Request Forgery
Booking Calendar <= 6.2 - Authenticated (Editor+) SQL Injection
Booking Calendar <= 6.2 - Cross-Site Request Forgery to SQL Injection
Booking Calendar <= 6.2 - Cross-Site Request Forgery leading to Cross-Site Scripting
Booking Calendar <= 4.1.5 - Cross-Site Request Forgery (CSRF)
Booking Calendar <= 6.2 - SQL Injection
Booking Calendar <= 6.2 - Reflected Cross-Site Scripting (XSS)
CVE-2022-33177
WordPress Booking Calendar plugin <= 4.1.5 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Booking Calendar plugin <= 6.2 - SQL Injection (SQLi) vulnerability
WordPress Booking Calendar plugin <= 6.2 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2022-1463
CVE-2017-2151
CVE-2017-2150
CVE-2018-20556
CVE-2021-25040