plugin

Booked Vulnerabilities

5 known security issues reported for the Booked WordPress plugin. Most recent disclosed Jul 2, 2026.

1 critical 1 high 3 medium

Running Booked on your site? Check whether your installed version is affected.

Scan your site free

Booked - Appointment Booking for WordPress <= 3.0.0 - Missing Authorization

medium

The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.0.0
Fix:
No patched version reported
Disclosed:
Jul 2, 2026

CVE-2026-57746 on NVD →

Booked - Appointment Booking for WordPress <= 3.0.0 - Cross-Site Request Forgery

medium

The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged...

CVSS:
4.3
Affected:
up to 3.0.0
Fix:
No patched version reported
Disclosed:
Jul 2, 2026

CVE-2026-57747 on NVD →

Booked <= 3.0.0 - Authentication Bypass

critical

The Booked - Appointment Booking for WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Custom-level access and above, to bypass authentication and access other user's accounts.

CVSS:
9.8
Affected:
up to 3.0.0
Fix:
No patched version reported
Disclosed:
Jan 29, 2026

CVE-2026-22341 on NVD →

Booked < 2.4.4 - Unauthenticated Sensitive Information Exposure

medium

The Booked plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and excluding, 2.4.4. This can allow unauthenticated attackers to extract sensitive appointment-related data from the database.

CVSS:
6.5
Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Jun 27, 2023

CVE-2022-36399 on NVD →

Booked <= 2.2.5 - Missing Authorization on AJAX Actions

high

The Booked plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions hooked via AJAX actions in versions up to, and including, 2.2.5. This makes it possible for authenticated attackers with subscriber-level permissions and above to execute several unauthorized acti...

CVSS:
8.8
Affected:
up to 2.2.6
Fixed in:
2.2.6
Disclosed:
Feb 29, 2020

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database