Appointment Booking Calendar
appointment-booking-calendar · plugin
Known security vulnerabilities for Appointment Booking Calendar. Find out in seconds which version runs on your site with WP Lens.
13 known vulnerabilities
2 critical · 6 exploitable without logging in · 2 with public exploit code · latest Jul 1, 2026
Listed on wordpress.org · latest 1.4.05 · last updated Aug 11, 2026 · 1K+ installs
wordpress.org status checked on Oct 4, 2026
Vulnerabilities
- Critical 9.8
CVE-2025-46247unauthenticated≤ 1.3.92
WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability
- Critical 9.8
CVE-2016-10916unauthenticated
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
- High 8.8
CVE-2025-46241unauthenticated · needs a click≤ 1.3.92
WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability
- High 8.8
CVE-2022-43482login required≤ 1.3.69
WordPress Appointment Booking Calendar plugin <= 1.3.69 - Missing Authorization vulnerability
- High 7.8
CVE-2020-9372unauthenticated · needs a click
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking
- High 7.5
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 fo
- Medium 6.1
CVE-2019-14791unauthenticated · needs a click
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
- Medium 5.4
CVE-2025-64261login required≤ 1.3.95
WordPress Appointment Booking Calendar plugin <= 1.3.95 - Broken Access Control vulnerability
- Medium 5.3
CVE-2025-13317unauthenticated≤ 1.3.96
Appointment Booking Calendar <= 1.3.96 - Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter
- Medium 4.8
CVE-2020-9371high privilege
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress.
- Medium 4.3
CVE-2026-12113contributor+≤ 1.4.02
Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure
- Medium 4.3
CVE-2026-12111contributor+≤ 1.4.01
Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter
- Medium 4.3
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calenda
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).