CVE-2022-47428: Wpdevart Booking Calendar

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.

Affected products

  • Wpdevart Booking Calendar: before 3.2.8 (fixed in 3.2.8)

Published 2023-11-06. Last modified 2026-06-17.