CVE-2018-5673: Booking Calendar Project Booking Calendar
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.
Affected products
- Booking Calendar Project Booking Calendar: version 2.1.7 only
Published 2018-01-13. Last modified 2026-06-17.