Appointment Booking Calendar

Information

Software Type Plugin
Software Slug appointment-booking-calendar (view on wordpress.org)
Software Status Active
Software Author codepeople
Software Website abc.dwbooster.com
Software Downloads 480,784
Software Active Installs 1,000
Software Record Last Updated August 17, 2026

16 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure Patched CVE-2026-12113 4.3 Wordfence PRISM June 30, 2026
Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter Patched CVE-2026-12111 4.3 Chloe Chamberland, Wordfence PRISM June 17, 2026
Appointment Booking Calendar <= 1.3.96 - Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter Patched CVE-2025-13317 5.3 Md. Moniruzzaman Prodhan (NomanProdhan) November 21, 2025
Appointment Booking Calendar <= 1.3.95 - Missing Authorization Patched CVE-2025-64261 4.3 daroo November 15, 2025
Appointment Booking Calendar <= 1.3.92 - Missing Authorization Patched CVE-2025-46247 5.3 timomangcut April 22, 2025
Appointment Booking Calendar <= 1.3.92 - Cross-Site Request Forgery to SQL Injection Patched CVE-2025-46241 6.5 astra.r3verii April 22, 2025
Appointment Booking Calendar <= 1.3.82 - Cross-Site Request Forgery Patched CVE-2024-0856 5.4 Sushil Phuyal February 28, 2024
Appointment Booking Calendar <= 1.3.69 - Missing Authorization Patched CVE-2022-43482 4.3 István Márton October 30, 2022
Appointment Booking Calendar <= 1.3.34 - Stored Cross-Site Scripting Patched CVE-2020-9371 4.8 March 4, 2020
Appointment Booking Calendar <= 1.3.34 - CSV Injection Patched CVE-2020-9372 7.8 Daniel Monzón March 4, 2020
Appointment Booking Calendar < 1.3.19 - Cross-Site Scripting Patched CVE-2019-14791 6.1 July 4, 2019
Appointment Booking Calendar <= 1.2.24 - SQL Injection Patched 9.8 Joaquin Ramirez Martinez January 27, 2016
Appointment Booking Calendar <= 1.2.24 - Cross-Site Scripting Patched 7.2 Joaquin Ramirez Martinez January 26, 2016
Appointment Booking Calendar <= 1.1.23 - SQL Injection Patched CVE-2016-10916 9.8 January 25, 2016
Appointment Booking Calendar <= 1.1.7 - Multiple Reflected Cross-Site Scripting Patched CVE-2015-7320 6.1 Ibéria Medeiros September 26, 2015
Appointment Booking Calendar <= 1.1.7 - SQL Injection Patched CVE-2015-7319 9.8 Ibéria Medeiros September 26, 2015

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation