
Booking Calendar Contact Form Security & Risk Analysis
wordpress.org/plugins/booking-calendar-contact-formBooking calendar form with a start and end date, or a single date option. Perfect for hotels, houses, services. PayPal payment integration included.
Is Booking Calendar Contact Form Safe to Use in 2026?
Generally Safe
Score 86/100Booking Calendar Contact Form has a strong security track record. Known vulnerabilities have been patched promptly.
The 'booking-calendar-contact-form' plugin exhibits a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and proper output escaping, significant concerns arise from the presence of the `unserialize` function and high-severity taint flows. The code analysis reveals a small attack surface with no unprotected entry points, which is a positive sign. However, the use of `unserialize` can be a major security risk if it processes user-supplied data, potentially leading to remote code execution vulnerabilities. The 7 high-severity taint flows with unsanitized paths strongly indicate potential vulnerabilities that could be exploited by attackers. The plugin's vulnerability history is also a significant concern, with a total of 8 known CVEs, including a past critical vulnerability and a high-severity one. The common types of vulnerabilities (missing authorization, XSS, CSRF, SQL injection) suggest recurring weaknesses in input validation and access control. The recent last vulnerability date also indicates ongoing security challenges. While the current version has no unpatched CVEs, the historical pattern and the critical taint flows suggest a continued need for vigilance and thorough auditing. Users should exercise caution and ensure they are running the latest version, though the potential for undiscovered vulnerabilities due to the `unserialize` function and the high-severity taint flows remains a notable risk.
Key Concerns
- High severity taint flows with unsanitized paths
- Use of dangerous function 'unserialize'
- Past critical CVE
- Past high severity CVE
- Common vulnerability types: Missing Auth, XSS, CSRF, SQLi
Booking Calendar Contact Form Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter
Booking Calendar Contact Form <= 1.2.58 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Booking Calendar Contact Form <= 1.2.55 - Authenticated (Administrator+) Stored Cross-Site Scripting
Booking Calendar Contact Form <= 1.2.40 - Reflected Cross-Site Scripting
Booking Calendar Contact Form <= 1.2.34 - Cross-Site Request Forgery via cpdexbccf_feedback
Booking Calendar Contact Form <= 1.0.23 - Reflected Cross-Site Scripting
Booking Calendar Contact Form < 1.0.24 - Blind SQL Injection
Booking Calendar Contact Form <= 1.0.23 - Shortcode SQL Injection
Booking Calendar Contact Form Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Booking Calendar Contact Form Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
Booking Calendar Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
Booking Calendar Contact Form Alternatives
MotoPress Booking Calendar
motopress-booking-calendar-lite
WordPress booking calendar plugin for daily, nightly, and hourly rentals.
WP Booking System – Booking Calendar
wp-booking-system
The booking calendar plugin for WordPress. Get easy online booking with this lightweight and powerful booking calendar.
Booking Package
booking-package
Booking Package is the simplest solution for integrating an online appointment booking calendar system and event calendar into your WordPress website.
FareHarbor for WordPress
fareharbor
Easily add FareHarbor reservation calendars, booking embeds, and buttons to your site.
Booking Activities
booking-activities
Reservation system specialized in activities: sports, leisure, courses, events, tourism, and more! Works great with WooCommerce.
Booking Calendar Contact Form Developer Profile
34 plugins · 89K total installs
How We Detect Booking Calendar Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.