Junglewise Threat Intelligence

CVE-2016-20070: CodePeople Booking Calendar Contact Form privilege escalation and stored XSS

CVE-2016-20070 · Severity: medium · CVSS 6.4 · Published 2026-06-15

Technologies: CodePeople Booking Calendar Contact Form. Vendors: CodePeople.

Executive brief

A vulnerability in the Booking Calendar Contact Form plugin for WordPress allows low-level users to gain unauthorized control over plugin settings. This flaw enables attackers to modify configuration options and inject malicious scripts into the website. If an administrator views the affected pages, the attacker could potentially hijack their session or perform actions on their behalf, compromising the site's security and visitor data.

Technical details

The Booking Calendar Contact Form plugin for WordPress (up to version 1.0.23) fails to perform adequate capability checks and input sanitization on several administrative functions. Authenticated attackers, including those with low-level 'Subscriber' roles, can exploit these flaws via the admin-ajax.php and admin.php endpoints. By manipulating parameters such as 'price', 'name', 'calendar_language', and 'email_confirmation_to_user', an attacker can modify plugin settings or store malicious JavaScript. This script executes in the context of any user (including administrators) who views the modified plugin settings or affected front-end pages, leading to stored Cross-Site Scripting (XSS). Additionally, the plugin was found to be vulnerable to unauthenticated blind SQL injection in the 'id' parameter of the 'dex_bccf_calendar_ajaxevent' action.

Affected products

  • CodePeople (DWBooster) Booking Calendar Contact Form <= 1.0.23

Timeline

  • 2016-02-08: disclosed: Initial discovery and exploit published by i0 SEC-LABORATORY
  • 2026-06-15: advisory: CVE-2016-20070 published/updated in NVD dataset

References

Related threats