Booking Calendar Contact Form <= 1.1.24 - Unauthenticated Stored Cross-Site Scripting
high
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.1.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe...
- CVSS:
- 7.2
- Affected:
- up to 1.1.24
- Fixed in:
- 1.1.25
- Disclosed:
- Jun 15, 2026
CVE-2016-20084 on NVD →
Booking Calendar Contact Form <= 1.0.23 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 1.0.23
- Fixed in:
- 1.0.24
- Disclosed:
- Jun 15, 2026
CVE-2016-20070 on NVD →
Booking Calendar Contact Form <= 1.2.63 - Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover
medium
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscri...
- CVSS:
- 5.3
- Affected:
- up to 1.2.63
- Fixed in:
- 1.2.64
- Disclosed:
- Apr 23, 2026
CVE-2026-6810 on NVD →
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.2.61
unknown
[en] The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 1.2.61
- Fixed in:
- 1.2.61
- Disclosed:
- Nov 22, 2025
CVE-2025-13318 on NVD →
Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter
medium
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to arbi...
- CVSS:
- 5.3
- Affected:
- up to 1.2.60
- Fixed in:
- 1.2.61
- Disclosed:
- Nov 21, 2025
CVE-2025-13318 on NVD →
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.2.59
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.58.
- Affected:
- up to 1.2.59
- Fixed in:
- 1.2.59
- Disclosed:
- Jul 4, 2025
CVE-2025-48231 on NVD →
Booking Calendar Contact Form <= 1.2.58 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.58 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 1.2.58
- Fixed in:
- 1.2.59
- Disclosed:
- Jun 30, 2025
CVE-2025-48231 on NVD →
Booking Calendar Contact Form <= 1.2.55 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.55 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web...
- CVSS:
- 4.4
- Affected:
- up to 1.2.55
- Fixed in:
- 1.2.56
- Disclosed:
- Jan 24, 2025
CVE-2025-24723 on NVD →
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.2.56
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.55.
- Affected:
- up to 1.2.56
- Fixed in:
- 1.2.56
- Disclosed:
- Jan 24, 2025
CVE-2025-24723 on NVD →
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.2.35
unknown
[en] Missing Authorization vulnerability in CodePeople Booking Calendar Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Calendar Contact Form: from n/a through 1.2.34.
- Affected:
- up to 1.2.35
- Fixed in:
- 1.2.35
- Disclosed:
- Dec 9, 2024
CVE-2023-25037 on NVD →
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.2.41
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.
- Affected:
- up to 1.2.41
- Fixed in:
- 1.2.41
- Disclosed:
- Jul 18, 2023
CVE-2023-36384 on NVD →
Booking Calendar Contact Form <= 1.2.40 - Reflected Cross-Site Scripting
medium
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dex_bccf_calendar_load2' parameter in versions up to, and including, 1.2.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.1
- Affected:
- up to 1.2.40
- Fixed in:
- 1.2.41
- Disclosed:
- Jun 22, 2023
CVE-2023-36384 on NVD →
Booking Calendar Contact Form <= 1.2.34 - Missing Authorization to Authenticated (Subscriber+) Feedback Form Submission
medium
The Booking Calendar Contact Form plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cpdexbccf_feedback function called via the cpdexbccf_feedback AJAX action in versions up to, and including, 1.2.34. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.3
- Affected:
- up to 1.2.34
- Fixed in:
- 1.2.35
- Disclosed:
- Feb 6, 2023
CVE-2023-25037 on NVD →
Booking Calendar Contact Form <= 1.2.34 - Cross-Site Request Forgery via cpdexbccf_feedback
medium
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.34. This is due to missing or incorrect nonce validation on the cpdexbccf_feedback function called via the cpdexbccf_feedback AJAX action. This makes it possible for unauthenticated a...
- CVSS:
- 4.3
- Affected:
- up to 1.2.34
- Fixed in:
- 1.2.35
- Disclosed:
- Feb 6, 2023
CVE-2023-25037 on NVD →
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.0.24
unknown
[en] The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
- Affected:
- up to 1.0.24
- Fixed in:
- 1.0.24
- Disclosed:
- Aug 21, 2019
CVE-2016-10908 on NVD →
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.0.24
unknown
[en] The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
- Affected:
- up to 1.0.24
- Fixed in:
- 1.0.24
- Disclosed:
- Aug 21, 2019
CVE-2016-10909 on NVD →
Booking Calendar Contact Form < 1.0.24 - Blind SQL Injection
critical
The Booking Calendar Contact Form plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter in versions up to, and including, 1.0.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to a...
- CVSS:
- 9.8
- Affected:
- up to 1.0.24
- Fixed in:
- 1.0.24
- Disclosed:
- Feb 8, 2016
CVE-2016-10909 on NVD →
Booking Calendar Contact Form <= 1.0.23 - Shortcode SQL Injection
high
The Booking Calendar Contact Form plugin for WordPress is vulnerable to SQL Injection via the ‘calendar’ atrribute in versions up to, and including, 1.0.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to ap...
- CVSS:
- 8.1
- Affected:
- up to 1.0.23
- Fixed in:
- 1.0.24
- Disclosed:
- Feb 8, 2016
CVE-2016-20068 on NVD →
Booking Calendar Contact Form <= 1.0.23 - Reflected Cross-Site Scripting
medium
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.0.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 1.0.23
- Fixed in:
- 1.0.24
- Disclosed:
- Feb 8, 2016
CVE-2016-10908 on NVD →
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.0.24
unknown
The Booking Calendar Contact Form plugin for WordPress is vulnerable to SQL Injection via the ‘calendar’ atrribute in versions up to, and including, 1.0.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to ap...
- Affected:
- up to 1.0.24
- Fixed in:
- 1.0.24
- Disclosed:
- Feb 8, 2016
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.0.24
unknown
This plugin is prone to multiple vulnerabilities, such as unauthenticated blind SQL injection, privilege escalation and stored XSS vulnerabilities.
Upgrade the plugin.
- Affected:
- up to 1.0.24
- Fixed in:
- 1.0.24
- Disclosed:
- Feb 8, 2016
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.1.25
unknown
This plugin is prone to persistent XSS vulnerabilities that appear in the administration page.
Upgrade the plugin.
- Affected:
- up to 1.1.25
- Fixed in:
- 1.1.25
- Disclosed:
- Jan 27, 2016
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.1.25
unknown
SQL injection is executed, when the action "cpabc_appointments_calendar_update" is called. Because of this vulnerability, an attacker can compromise all the web server.
Update the plugin.
- Affected:
- up to 1.1.25
- Fixed in:
- 1.1.25
- Disclosed:
- Jan 27, 2016
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.1.24
unknown
This vulnerability can be exploited by adding crafted shortcodes on a page or post. Because of it, an attacker can compromise all web server.
Upgrade the plugin.
- Affected:
- up to 1.1.24
- Fixed in:
- 1.1.24
- Disclosed:
- Jan 26, 2016
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.1.24
unknown
This WordPress Booking Calendar Contact Form plugin's "action=cpabc_appointments_check_IPN_verification" parameter is prone to an unauthenticated SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Upd...
- Affected:
- up to 1.1.24
- Fixed in:
- 1.1.24
- Disclosed:
- Jan 25, 2016
Booking Calendar Contact Form [booking-calendar-contact-form] < 1.0.3
unknown
Booking Calendar Contact Form plugin is prone to multiple vulnerabilities:
1. Authenticated SQL injection in "get" parameter allows an attacker to escalate editor privileges.
2. Filter bypass & Authenticated SQL injection in "id" parameter via http://wp-host/wp-path/wp-admin/admin-ajax.php?action=dex_bccf_calendar_a...
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.3
- Disclosed:
- May 13, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database