Known vulnerabilities in the Appointment Booking Calendar plugin
16 security advisories have been published for the Appointment Booking Calendar plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Appointment Booking Calendar - Information Disclosure (CVE-2026-12113) MEDIUM
- Appointment Booking Calendar - Cross-Site Scripting (XSS) (CVE-2026-1856) MEDIUM
- Appointment Booking Calendar - Information Disclosure (CVE-2026-12111) MEDIUM
- Appointment Booking Calendar - Broken Access Control (CVE-2026-6937) MEDIUM
- Appointment Booking Calendar - SQL Injection (CVE-2026-7797) HIGH
- Appointment Booking Calendar - Denial of Service (CVE-2026-7493) MEDIUM
- Appointment Booking Calendar - Broken Access Control (CVE-2026-4807) MEDIUM
- Appointment Booking Calendar - SQL Injection (CVE-2026-3658) HIGH
- Appointment Booking Calendar - Security Vulnerability (CVE-2026-3045) HIGH
- Appointment Booking Calendar - Security Vulnerability (CVE-2026-1704) MEDIUM
- Appointment Booking Calendar - SQL Injection (CVE-2026-1708) HIGH
- Appointment Booking Calendar Plugin - Broken Access Control (CVE-2026-1932) MEDIUM
- Appointment Booking Calendar - Broken Access Control (CVE-2025-13317) MEDIUM
- Appointment Booking Calendar - Cross-Site Scripting (XSS) (CVE-2024-13431) MEDIUM
- Appointment Booking Calendar - Security Vulnerability (CVE-2024-12274) HIGH
- Appointment Booking Calendar - Remote Code Execution (CVE-2024-7129) HIGH
- Appointment Booking Calendar - Cross-Site Request Forgery (CSRF) (CVE-2024-0856) HIGH