VendorsCodePeopleappointment_booking_calendarany version
Vulnerabilities

CodePeople Appointment Booking Calendar any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2016-10916
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
Published 2019-08-22 · Modified
9.8EPSS 0.018
CVE-2025-46247
WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability
Published 2025-04-22 · Modified
9.8EPSS 0.004
CVE-2022-43482
WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability
Published 2022-11-18 · Modified
8.8EPSS 0.005
CVE-2024-0856
Booking Calendar < 1.3.83 - CSRF appointment scheduling
Published 2024-03-20 · Analyzed
8.8EPSS 0.004
CVE-2025-46241
WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability
Published 2025-04-22 · Modified
8.8EPSS 0.002
CVE-2020-9372
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.
Published 2020-03-04 · Modified
7.81 PoCEPSS 0.086
CVE-2015-7319
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.
Published 2015-09-29 · Modified
7.5EPSS 0.024
CVE-2024-12274
BookingPress < 1.1.23 - Unauthenticated Export File Download
Published 2025-01-13 · Analyzed
7.5EPSS 0.006
CVE-2020-9371
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML.
Published 2020-03-04 · Modified
4.81 PoCEPSS 0.033
CVE-2015-7320
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-09-29 · Modified
4.3EPSS 0.021