Codepeople develops a focused suite of WordPress plugins and form-building solutions including Calculated Fields Form, Appointment Booking Calendar, Contact Form by Email, and Time Slots Booking Form that serve small-to-medium web publishers and service providers. The vendor's vulnerability profile concentrates around web-application input-handling and access-control flaws, with recurring weakness classes including cross-site scripting, SQL injection, missing authorization, and cross-site request forgery that are characteristic of plugin-based WordPress development. A meaningful share of disclosed vulnerabilities reach serious severity outcomes, reflecting the risk posture of publicly exposed form and calendar interfaces that process user input and manage booking or appointment data. Defenders deploying these plugins should prioritize keeping them current and restrict plugin administrative capabilities; live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codepeople over time
Signals from CVEs in this vendor scope (90 CVEs).
90 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9372HIGH The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then coul | Mar 4, 2020 | 7.8 | 38 | NO | YES |
CVE-2026-57670HIGH Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions. | Jul 2, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-48882HIGH Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions. | Jun 15, 2026 | 8.5 | 30 | NO | NO |
CVE-2015-10099CRITICAL A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of t | Apr 10, 2023 | 9.8 | 30 | NO | NO |
CVE-2014-125091CRITICAL A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message | Mar 4, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-9371MEDIUM Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to injec | Mar 4, 2020 | 4.8 | 28 | NO | YES |
CVE-2026-40791HIGH Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions. | Jun 15, 2026 | 7.1 | 27 | NO | NO |
CVE-2026-32433HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blin | Mar 13, 2026 | 8.5 | 27 | NO | NO |
CVE-2025-68569HIGH Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This | Dec 24, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-46247CRITICAL Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This iss | Apr 22, 2025 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (90 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codepeople.
Media articles that mention a CVE ID that affects a product developed by Codepeople — matched by CVE ID, not by vendor name.