What the vulnerability does
01Description
Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
Explanation of Vulnerability in Simple Terms
02Summary
The Booking Calendar plugin for WordPress fails to properly check user permissions before allowing access to certain administrative functions. A logged-in user with low privileges can read, modify, or delete booking data and settings without proper authorization. The vulnerability requires network access and some attack complexity, but no user interaction from the victim.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete booking data and plugin settings without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can tamper with bookings, appointments, and plugin configuration, disrupting your booking system.
Conditions required to exploit
05Prerequisites
Attacker must be logged in as a low-privilege user (subscriber or contributor). Network access required.
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 28, 2026
Record updated