Cross-Site Scripting
15 records50%First: 2016. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 30 vulnerability records associated with Booking Calendar, published between 2014 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 1 | |
| 2016 | 3 | |
| 2018 | 1 | |
| 2021 | 1 | |
| 2022 | 2 | |
| 2023 | 3 | |
| 2024 | 6 | |
| 2025 | 7 | |
| 2026 | 6 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 3.3% |
| High | 7 | 23.3% |
| Medium | 22 | 73.3% |
First: 2016. Latest: 2026.
First: 2016. Latest: 2026.
First: 2025. Latest: 2026.
First: 2014. Latest: 2022.
First: 2022. Latest: 2022.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
11.4.310.14.1510.14.1610.14.1410.14.1210.14.1110.14.910.14.710.14.810.14.210.11.210.10.110.9.310.6.510.6.310.6.110.5.110.2.29.9.19.7.49.7.3.19.4.3.19.2.29.1.18.9.28.4.46.2.14.1.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-11.4.2 | Booking Calendar <= 11.4.2 - Unauthenticated Stored Cross-Site Scripting | July 27, 2026 | 11.4.3 | High |
*-10.14.14 | Booking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification | February 17, 2026 | 10.14.15 | Medium |
*-10.14.15 | Booking Calendar <= 10.14.15 - Authenticated (Editor+) SQL Injection | February 14, 2026 | 10.14.16 | Medium |
*-10.14.13 | Booking Calendar <= 10.14.13 - Missing Authorization to Unauthenticated Booking Details Exposure | January 30, 2026 | 10.14.14 | Medium |
*-10.14.11 | Booking Calendar <= 10.14.11 - Missing Authorization to Sensitive Information Exposure | January 15, 2026 | 10.14.12 | Medium |
*-10.14.10 | Booking Calendar <= 10.14.10 - Unauthenticated Sensitive Information Exposure | January 8, 2026 | 10.14.11 | Medium |
*-10.14.8 | Booking Calendar <= 10.14.8 - Unauthenticated SQL Injection via dates_to_check | December 15, 2025 | 10.14.9 | High |
*-10.14.6 | Booking Calendar <= 10.14.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via bookingcalendar Shortcode | December 4, 2025 | 10.14.7 | Medium |
*-10.14.7 | Booking Calendar <= 10.14.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | November 13, 2025 | 10.14.8 | Medium |
*-10.14.1 | Booking Calendar <= 10.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | August 27, 2025 | 10.14.2 | Medium |
*-10.11.1 | Booking Calendar <= 10.11.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpbc Shortcode | May 16, 2025 | 10.11.2 | Medium |
*-10.10 | WP Booking Calendar <= 10.10 - Unauthenticated Post-Confirmation Booking Manipulation | February 11, 2025 | 10.10.1 | Medium |
*-10.9.2 | Booking Calendar <= 10.9.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'booking' Shortcode | January 13, 2025 | 10.9.3 | Medium |
*-10.6.4 | WP Booking Calendar <= 10.6.4 - Authenticated (Admin+) Stored Cross-Site Scripting | November 14, 2024 | 10.6.5 | Medium |
*-10.6.2 | WP Booking Calendar <= 10.6.2 - Authenticated (Administrator+) Stored Cross-Site Scripting | October 17, 2024 | 10.6.3 | Medium |
*-10.6 | WP Booking Calendar <= 10.6 - Authenticated (Admin+) Stored Cross-Site Scripting | October 3, 2024 | 10.6.1 | Medium |
*-10.5 | WP Booking Calendar <= 10.5 - Reflected Cross-Site Scripting | August 29, 2024 | 10.5.1 | Medium |
*-10.2.1 | WP Booking Calendar <= 10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via bookingform Shortcode | July 23, 2024 | 10.2.2 | Medium |
*-9.9 | Booking Calendar <= 9.9 - Unauthenticated SQL Injection | February 7, 2024 | 9.9.1 | Critical |
[*, 9.7.4) | Booking Calendar <= 9.7.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode | September 25, 2023 | 9.7.4 | Medium |
*-9.7.3 | Booking Calendar <= 9.7.3 - Unauthenticated Stored Cross-Site Scripting | September 11, 2023 | 9.7.3.1 | Medium |
*-9.4.2 | Booking Calendar <= 9.4.2 - Authenticated (Admin+) SQL Injection | January 20, 2023 | 9.4.3.1 | Medium |
*-9.2.1 | Booking Calendar <= 9.2.1 - Cross-Site Request Forgery | September 6, 2022 | 9.2.2 | Medium |
*-9.1 | Booking Calendar <= 9.1 - PHP Object Injection via Shortcode | April 18, 2022 | 9.1.1 | High |
*-8.9.1 | Booking Calendar <= 8.9.1 - Reflected Cross-Site Scripting | December 6, 2021 | 8.9.2 | Medium |
Selected source records
Published: July 27, 2026
Published: February 17, 2026
Published: February 14, 2026
Published: January 30, 2026
Published: January 15, 2026
Published: January 8, 2026
Published: December 15, 2025
Published: December 4, 2025
Published: February 7, 2024
Published: August 1, 2016
Published: December 28, 2018
Published: August 1, 2016
Published: April 18, 2022
Published: December 15, 2025
Published: July 27, 2026
Published: August 1, 2016
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.