SQL Injection
6 records33.3%First: 2022. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 18 vulnerability records associated with Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress, published between 2022 and 2025.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2022 | 3 | |
| 2023 | 4 | |
| 2024 | 9 | |
| 2025 | 2 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 11.1% |
| High | 6 | 33.3% |
| Medium | 10 | 55.6% |
First: 2022. Latest: 2025.
First: 2022. Latest: 2024.
First: 2023. Latest: 2024.
First: 2023. Latest: 2024.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
First: 2024. Latest: 2024.
First: 2025. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.1.381.1.261.1.221.1.231.1.171.1.81.1.61.0.831.0.821.0.881.0.751.0.731.0.771.0.651.0.311.0.141.0.11Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.1.28 | BookingPress <= 1.1.28 - Authenticated (Administrator+) SQL Injection | April 1, 2025 | 1.1.38 | Medium |
*-1.1.25 | BookingPress <= 1.1.25 - Authenticated (Contributor+) Stored Cross-Site Scripting | January 24, 2025 | 1.1.26 | Medium |
*-1.1.21 | Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress <= 1.1.21 - Authenticated (Contributor+) SQL Injection | December 23, 2024 | 1.1.22 | Medium |
*-1.1.22 | BookingPress <= 1.1.22 - Unauthenticated File Export Download | December 23, 2024 | 1.1.23 | Medium |
*-1.1.16 | Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection | November 1, 2024 | 1.1.17 | Medium |
1.1.6-1.1.7 | Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover | August 7, 2024 | 1.1.8 | Critical |
*-1.1.5 | BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload | July 16, 2024 | 1.1.6 | High |
*-1.1.5 | BookingPress Appointment Booking <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation | July 16, 2024 | 1.1.6 | High |
*-1.0.82 | BookingPress <= 1.0.82 - Missing Authorization to Appointment Time Alteration | May 20, 2024 | 1.0.83 | Medium |
*-1.0.81 | BookingPress <= 1.0.81 - Authenticated (Customer+) Insecure Direct Object Reference | April 5, 2024 | 1.0.82 | Medium |
*-1.0.87 | BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.87 - Authenticated (Admin+) Arbitrary File Upload | April 3, 2024 | 1.0.88 | High |
*-1.0.74 | BookingPress <= 1.0.74 - Booking Price Manipulation via bookingpress_confirm_booking | December 27, 2023 | 1.0.75 | High |
*-1.0.72 | BookingPress <= 1.0.72 - Authenticated (Contributor+) SQL Injection | December 21, 2023 | 1.0.73 | High |
*-1.0.76 | BookingPress <= 1.0.76 - Authenticated (Administrator+) Arbitrary File Upload | November 27, 2023 | 1.0.77 | High |
*-1.0.64 | BookingPress <= 1.0.64 - Unauthenticated Sensitive Information Exposure | July 13, 2023 | 1.0.65 | Medium |
*-1.0.30 | BookingPress <= 1.0.30 - Unauthenticated Insecure Direct Object Reference | December 7, 2022 | 1.0.31 | Medium |
*-1.0.13 | BookingPress – Appointments Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.13 - SQL Injection | April 8, 2022 | 1.0.14 | Medium |
[*, 1.0.11) | BookingPress < 1.0.11 - SQL Injection | February 28, 2022 | 1.0.11 | Critical |
Selected source records
Published: April 1, 2025
Published: January 24, 2025
Published: December 23, 2024
Published: December 23, 2024
Published: November 1, 2024
Published: August 7, 2024
Published: July 16, 2024
Published: July 16, 2024
Published: August 7, 2024
Published: February 28, 2022
Published: July 16, 2024
Published: July 16, 2024
Published: December 21, 2023
Published: December 27, 2023
Published: April 3, 2024
Published: November 27, 2023
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.