Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 18 vulnerability records associated with Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress, published between 2022 and 2025.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

18Total records
2Critical
6High
10Medium
0Low
0Informational
18Patched records
0Currently marked unpatched
2022-02-28First disclosure
2025-04-01Latest disclosure
17 of 18CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202233 records
202344 records
202499 records
202522 records

Severity Breakdown

SeverityRecordsShare
Critical211.1%
High633.3%
Medium1055.6%

Vulnerability-Type Breakdown

SQL Injection

6 records33.3%

First: 2022. Latest: 2025.

Missing Authorization

4 records22.2%

First: 2022. Latest: 2024.

Arbitrary File Upload

2 records11.1%

First: 2023. Latest: 2024.

Other

2 records11.1%

First: 2023. Latest: 2024.

Information Disclosure

1 record5.6%

First: 2023. Latest: 2023.

Path Traversal

1 record5.6%

First: 2024. Latest: 2024.

Authentication Bypass

1 record5.6%

First: 2024. Latest: 2024.

Cross-Site Scripting

1 record5.6%

First: 2025. Latest: 2025.

Patch Status

Patched
18
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 1.1.38
  • 1.1.26
  • 1.1.22
  • 1.1.23
  • 1.1.17
  • 1.1.8
  • 1.1.6
  • 1.0.83
  • 1.0.82
  • 1.0.88
  • 1.0.75
  • 1.0.73
  • 1.0.77
  • 1.0.65
  • 1.0.31
  • 1.0.14
  • 1.0.11

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-1.1.28BookingPress <= 1.1.28 - Authenticated (Administrator+) SQL InjectionApril 1, 20251.1.38Medium
*-1.1.25BookingPress <= 1.1.25 - Authenticated (Contributor+) Stored Cross-Site ScriptingJanuary 24, 20251.1.26Medium
*-1.1.21Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress <= 1.1.21 - Authenticated (Contributor+) SQL InjectionDecember 23, 20241.1.22Medium
*-1.1.22BookingPress <= 1.1.22 - Unauthenticated File Export DownloadDecember 23, 20241.1.23Medium
*-1.1.16Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL InjectionNovember 1, 20241.1.17Medium
1.1.6-1.1.7Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account TakeoverAugust 7, 20241.1.8Critical
*-1.1.5BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File UploadJuly 16, 20241.1.6High
*-1.1.5BookingPress Appointment Booking <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File CreationJuly 16, 20241.1.6High
*-1.0.82BookingPress <= 1.0.82 - Missing Authorization to Appointment Time AlterationMay 20, 20241.0.83Medium
*-1.0.81BookingPress <= 1.0.81 - Authenticated (Customer+) Insecure Direct Object ReferenceApril 5, 20241.0.82Medium
*-1.0.87BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.87 - Authenticated (Admin+) Arbitrary File UploadApril 3, 20241.0.88High
*-1.0.74BookingPress <= 1.0.74 - Booking Price Manipulation via bookingpress_confirm_bookingDecember 27, 20231.0.75High
*-1.0.72BookingPress <= 1.0.72 - Authenticated (Contributor+) SQL InjectionDecember 21, 20231.0.73High
*-1.0.76BookingPress <= 1.0.76 - Authenticated (Administrator+) Arbitrary File UploadNovember 27, 20231.0.77High
*-1.0.64BookingPress <= 1.0.64 - Unauthenticated Sensitive Information ExposureJuly 13, 20231.0.65Medium
*-1.0.30BookingPress <= 1.0.30 - Unauthenticated Insecure Direct Object ReferenceDecember 7, 20221.0.31Medium
*-1.0.13BookingPress – Appointments Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.13 - SQL InjectionApril 8, 20221.0.14Medium
[*, 1.0.11)BookingPress < 1.0.11 - SQL InjectionFebruary 28, 20221.0.11Critical

Selected source records

Latest Records

MediumCVE-2025-31910

BookingPress <= 1.1.28 - Authenticated (Administrator+) SQL Injection

Published: April 1, 2025

Affected versions
*-1.1.28
Patched versions
1.1.38
Original Wordfence record
MediumCVE-2025-24732

BookingPress <= 1.1.25 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: January 24, 2025

Affected versions
*-1.1.25
Patched versions
1.1.26
Original Wordfence record
MediumCVE-2024-12274

BookingPress <= 1.1.22 - Unauthenticated File Export Download

Published: December 23, 2024

Affected versions
*-1.1.22
Patched versions
1.1.23
Original Wordfence record
MediumCVE-2024-11726

Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress <= 1.1.21 - Authenticated (Contributor+) SQL Injection

Published: December 23, 2024

Affected versions
*-1.1.21
Patched versions
1.1.22
Original Wordfence record
MediumCVE-2024-10540

Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection

Published: November 1, 2024

Affected versions
*-1.1.16
Patched versions
1.1.17
Original Wordfence record
CriticalCVE-2024-7350

Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover

Published: August 7, 2024

Affected versions
1.1.6-1.1.7
Patched versions
1.1.8
Original Wordfence record
HighCVE-2024-6660

BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload

Published: July 16, 2024

Affected versions
*-1.1.5
Patched versions
1.1.6
Original Wordfence record
HighCVE-2024-6467

BookingPress Appointment Booking <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation

Published: July 16, 2024

Affected versions
*-1.1.5
Patched versions
1.1.6
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-7350

Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover

Published: August 7, 2024

Affected versions
1.1.6-1.1.7
Patched versions
1.1.8
Original Wordfence record
CriticalCVE-2022-0739

BookingPress < 1.0.11 - SQL Injection

Published: February 28, 2022

Affected versions
[*, 1.0.11)
Patched versions
1.0.11
Original Wordfence record
HighCVE-2024-6660

BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload

Published: July 16, 2024

Affected versions
*-1.1.5
Patched versions
1.1.6
Original Wordfence record
HighCVE-2024-6467

BookingPress Appointment Booking <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation

Published: July 16, 2024

Affected versions
*-1.1.5
Patched versions
1.1.6
Original Wordfence record
HighCVE-2023-50841

BookingPress <= 1.0.72 - Authenticated (Contributor+) SQL Injection

Published: December 21, 2023

Affected versions
*-1.0.72
Patched versions
1.0.73
Original Wordfence record
HighCVE-2023-51405

BookingPress <= 1.0.74 - Booking Price Manipulation via bookingpress_confirm_booking

Published: December 27, 2023

Affected versions
*-1.0.74
Patched versions
1.0.75
Original Wordfence record
HighCVE-2024-3022

BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.87 - Authenticated (Admin+) Arbitrary File Upload

Published: April 3, 2024

Affected versions
*-1.0.87
Patched versions
1.0.88
Original Wordfence record
HighCVE-2023-6219

BookingPress <= 1.0.76 - Authenticated (Administrator+) Arbitrary File Upload

Published: November 27, 2023

Affected versions
*-1.0.76
Patched versions
1.0.77
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory