Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpbookingcalendar

First CVE: Sep 6, 2022Active for: 4 yearsTotal CVEs: 13
10.6
VTI Score
Low

Wpbookingcalendar is a modestly represented WordPress plugin and application suite centered on booking and calendar functionality, with exposure spanning products such as Booking Calendar, WP Booking Calendar, and Secure Downloads. The recurring vulnerability signal reflects common web-application patterns: cross-site scripting and SQL injection in form handling and data processing, cross-site request forgery in state-changing operations, and authorization and access-control gaps that expose calendars or file resources to unintended actors. A meaningful share of disclosed vulnerabilities reach serious severity. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpbookingcalendar over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 6, 2022
3 years ago
Most Recent CVE
May 17, 2025
433 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-1207CRITICAL
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9
Feb 8, 20249.832NONO
CVE-2023-4620MEDIUM
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripti
Oct 16, 20236.119NONO
CVE-2024-8031MEDIUM
The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with
May 15, 20256.518NONO
CVE-2024-10027MEDIUM
The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform St
Nov 7, 20244.818NONO
CVE-2024-8274MEDIUM
The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5 d
Aug 30, 20246.118NONO
CVE-2022-33177MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress leading to Translations Update.
Sep 6, 20224.318NONO
CVE-2024-13323MEDIUM
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to i
Jan 14, 20255.417NONO
CVE-2024-9306MEDIUM
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sa
Oct 4, 20244.817NONO
CVE-2024-6930MEDIUM
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions up to,
Jul 24, 20245.417NONO
CVE-2025-4669MEDIUM
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insuf
May 17, 20255.416NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
92%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (23.1%)
Unknown0 (0.0%)
Required10 (76.9%)
Privileges Required
Low5 (38.5%)
High3 (23.1%)
None5 (38.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpbookingcalendar.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpbookingcalendar — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpbookingcalendar's Products

View all 3 CNAs →

Top CWEs