WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Easy Appointment Booking & Scheduling System – Webba Booking Calendar

Free Appointment Booking Plugin 🗓️ Hourly or full-day bookings, booking management, calendar sync, notifications, 5* support = powerful booking syste …

8Reported vulnerabilities
5.3Highest CVSS score
6.4.20Latest version
2,000+Active installs

What to do now

Update Easy Appointment Booking & Scheduling System – Webba Booking Calendar to 6.4.14 or later. 8 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-27409 Medium 5.3 0.3% 6.4.13 and earlier 6.4.14 July 1, 2026
CVE-2025-54040 Medium 5.3 0.4% 5.1.20 and earlier 5.1.22 July 16, 2025
CVE-2021-36847 Medium 4.8 0.6% Before 4.2.22 4.2.22 August 22, 2022
CVE-2025-66530 Medium 4.3 0.3% 6.2.1 and earlier 6.2.2 December 15, 2025
CVE-2025-54729 Medium 4.4 0.2% 6.0.5 and earlier 6.0.6 August 14, 2025
CVE-2025-54036 Medium 4.3 0.1% 5.1.20 and earlier 5.1.21 July 16, 2025
CVE-2024-8432 Medium 4.3 0.4% Before 5.0.50 5.0.50 September 24, 2024
CVE-2023-51354 Medium 4.3 0.2% 4.5.33 and earlier 5.0 December 26, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.