CVE-2018-5673: Booking Calendar Project Booking Calendar

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.

Affected products

Published 2018-01-13. Last modified 2026-06-17.