Executive brief
The Appointment Booking Calendar plugin for WordPress, used for managing online reservations and PayPal payments, contains security flaws that allow unauthorized individuals to change calendar settings. Attackers can also plant malicious scripts that run when a site administrator or visitor views the calendar. This could lead to unauthorized access to the website's management interface or the theft of sensitive user information.
Technical details
The Appointment Booking Calendar plugin (also known as Booking Calendar Contact Form) for WordPress is vulnerable to privilege escalation and stored Cross-Site Scripting (XSS) due to insufficient access controls and input sanitization in the 'admin.php' page. Unauthenticated attackers can send crafted GET requests to modify plugin options such as 'ict', 'ics', and the calendar 'name' parameter. This allows for the injection of persistent JavaScript payloads that execute in the context of an administrative user's session or a site visitor's browser. The vulnerability stems from the plugin failing to verify administrative privileges before processing configuration updates.
Affected products
- CodePeople Appointment Booking Calendar (Booking Calendar Contact Form) <= 1.1.24
Timeline
- 2016-01-08: other: Vulnerability discovered
- 2016-01-24: other: Reported to vendor
- 2016-01-27: disclosed: Public exploit released on Exploit-DB
- 2026-06-15: advisory: NVD/VulnCheck advisory published