Known vulnerabilities in Bookit — Booking & Appointment Calendar
Appointment booking and event calendar for WordPress. Services, staff, availability, shortcodes, and email notifications. Prevents double-booking.
5Reported vulnerabilities
9.8Highest CVSS score
2.6.0.1Latest version
4,000+Active installs
What to do now
Update Bookit — Booking & Appointment Calendar to 2.5.4.1 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2023-2834 | Critical | 1.9% | 2.3.7 and earlier | 2.3.8 |
June 30, 2023 |
| CVE-2025-12633 | High | 0.3% | 0 to 2.5.0 (inclusive) | 2.5.1 |
November 12, 2025 |
| CVE-2023-50852 | Medium | 0.5% | Before 2.4.4 | 2.4.4 |
December 21, 2023 |
| CVE-2025-12841 | Medium | 0.7% | 0 up to (but not including) 2.5.1 | 2.5.1 |
December 12, 2025 |
| CVE-2026-40780 | Medium | 0.3% | 2.5.1 and earlier | 2.5.4.1 |
April 22, 2026 |