Skip to content
Noroxi

Appointment Booking Calendar

appointment-booking-calendar · plugin

Known security vulnerabilities for Appointment Booking Calendar. Find out in seconds which version runs on your site with WP Lens.

13 known vulnerabilities

2 critical · 6 exploitable without logging in · 2 with public exploit code · latest Jul 1, 2026

Listed on wordpress.org · latest 1.4.05 · last updated Aug 11, 2026 · 1K+ installs

wordpress.org status checked on Oct 4, 2026

Vulnerabilities

  • CVE-2025-46247unauthenticated≤ 1.3.92

    WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability

    Critical 9.8
  • CVE-2016-10916unauthenticated

    The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.

    Critical 9.8
  • CVE-2025-46241unauthenticated · needs a click≤ 1.3.92

    WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability

    High 8.8
  • CVE-2022-43482login required≤ 1.3.69

    WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability

    High 8.8
  • CVE-2020-9372unauthenticated · needs a click

    The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking

    High 7.8
  • CVE-2015-7319

    SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 fo

    High 7.5
  • CVE-2019-14791unauthenticated · needs a click

    The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.

    Medium 6.1
  • CVE-2025-64261login required≤ 1.3.95

    WordPress Appointment Booking Calendar plugin <= 1.3.95 - Broken Access Control vulnerability

    Medium 5.4
  • CVE-2025-13317unauthenticated≤ 1.3.96

    Appointment Booking Calendar <= 1.3.96 - Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter

    Medium 5.3
  • CVE-2020-9371high privilege

    Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress.

    Medium 4.8
  • CVE-2026-12113contributor+≤ 1.4.02

    Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure

    Medium 4.3
  • CVE-2026-12111contributor+≤ 1.4.01

    Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter

    Medium 4.3
  • CVE-2015-7320

    Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calenda

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory

Appointment Booking Calendar — WordPress plugin vulnerabilities — Noroxi