WordPress security by component
Booking Calendar Contact Form
Plugin description
Booking Calendar Contact Form is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
booking-calendar-contact-formLatest vulnerability
CVE-2016-20070: Booking Calendar Contact Form: Cross-site scripting
Booking Calendar Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.0.23.
| Safe version |
|
||
|---|---|---|---|
| Jun 15, 2026 |
CVE-2016-20070
Booking Calendar Contact Form: Cross-site scripting
Booking Calendar Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.0.23.
|
> 1.0.23 |
CVE5.1
NVDPending
|
| Jun 15, 2026 |
CVE-2016-20069
Booking Calendar Contact Form: SQL injection
Booking Calendar Contact Form is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.0.23.
|
> 1.0.23 |
CVE8.8
NVDPending
|
| Jun 15, 2026 |
CVE-2016-20068
Booking Calendar Contact Form: SQL injection
Booking Calendar Contact Form is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.0.23.
|
> 1.0.23 |
CVE8.8
NVDPending
|
| Apr 24, 2026 |
CVE-2026-6810
Booking Calendar Contact Form: A security weakness
Booking Calendar Contact Form is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.2.63.
|
> 1.2.63 |
CVE5.3
NVDPending
|
| Nov 22, 2025 |
CVE-2025-13318
Booking Calendar Contact Form: A security weakness
Booking Calendar Contact Form is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jul 04, 2025 |
CVE-2025-48231
Booking Calendar Contact Form: Cross-site scripting
Booking Calendar Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 24, 2025 |
CVE-2025-24723
Booking Calendar Contact Form: Cross-site scripting
Booking Calendar Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Dec 09, 2024 |
CVE-2023-25037
Booking Calendar Contact Form: A security weakness
Booking Calendar Contact Form is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jul 18, 2023 |
CVE-2023-36384
Booking Calendar Contact Form: Cross-site scripting
Booking Calendar Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Aug 21, 2019 |
CVE-2016-10909
Booking Calendar Contact Form: SQL injection
Booking Calendar Contact Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Aug 21, 2019 |
CVE-2016-10908
Booking Calendar Contact Form: Cross-site scripting
Booking Calendar Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|