
Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings Security & Risk Analysis
wordpress.org/plugins/bookingorBookingor is a Great Booking System for Appointment Booking Plugin. Schedule Booking Calendar events, meeting scheduler, Automated book appointment
Is Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings Safe to Use in 2026?
Mostly Safe
Score 76/100Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings is generally safe to use. 2 past CVEs were resolved.
The "bookingor" plugin version 2.0.14 exhibits a concerning security posture, primarily due to a large number of unprotected AJAX handlers. While the plugin demonstrates good practices in SQL query preparation and output escaping, the sheer volume of exposed entry points (71 out of 80 total) significantly increases the attack surface. This lack of authentication checks on AJAX endpoints presents a high risk for unauthorized actions. The taint analysis revealing two high-severity flows with unsanitized paths further exacerbates these concerns, indicating potential for malicious data manipulation or execution if these flows are triggered. The vulnerability history, particularly the presence of two medium-severity CVEs and one currently unpatched vulnerability, points to a recurring pattern of missing authorization, reinforcing the findings from the static analysis. Although the plugin has strengths in its handling of SQL and output, the identified weaknesses in authorization and the presence of unpatched vulnerabilities are critical issues that require immediate attention. The unpatched CVE is a significant risk as it's a known vulnerability that could be exploited.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Unpatched CVE
- Recurring missing authorization vulnerabilities
- Bundled DataTables library
- Bundled Select2 library
- Bundled Guzzle library
Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Bookingor <= 1.0.12 - Missing Authorization
Bookingor <= 2.0.1 - Missing Authorization
Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings Release Timeline
Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings Attack Surface
AJAX Handlers 71
Shortcodes 9
WordPress Hooks 35
Maintenance & Trust
Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings Maintenance & Trust
Maintenance Signals
Community Trust
Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings Alternatives
Easy Appointment Booking & Scheduling System – Webba Booking Calendar
webba-booking-lite
Free Appointment Booking Plugin 📅 Unlimited appointments, booking management, calendar sync, notifications, 5* support = powerful booking system!
Timetics – Appointment Booking & Scheduling
timetics
Appointment booking and scheduling system with online booking calendar, payments, automated reminders, and calendar sync.
Booking System Trafft
booking-system-trafft
Trafft is a next-level booking system offering limitless opportunities for scheduling appointments and managing your calendar & all of your bookings.
Easy Booked – Appointment Booking and Scheduling Management System for WordPress
easy-booked
A comprehensive appointment booking calendar and scheduling management system for WordPress.
Quill Booking – Appointment Scheduling & Event Management Solution
quillbooking
Enterprise-grade appointment scheduling and event management platform designed for modern businesses and service providers.
Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings Developer Profile
1 plugin · 80 total installs
How We Detect Bookingor – Booking System for Appointment Calendar, Meeting Scheduler & WooCommerce Bookings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bookingor/assets/css/bookingor-public.css/wp-content/plugins/bookingor/assets/js/bookingor-public.js/wp-content/plugins/bookingor/assets/js/bookingor-public.jsbookingor/assets/css/bookingor-public.css?ver=bookingor/assets/js/bookingor-public.js?ver=HTML / DOM Fingerprints
bookingor-buttonbookingor-btn-wrapbookingor-btnbookingor-booking-sectiondata-bookingor-iddata-bookingor-service-idbookingorAppbookingor_data/wp-json/bookingor/v1/get_services/wp-json/bookingor/v1/get_appointments[bookingor_booking_form][bookingor_appointment_calendar][bookingor_button]