Junglewise Threat Intelligence

CVE-2026-27377: AxiomThemes QuickCal broken access control in WordPress plugin

CVE-2026-27377 · Severity: medium · CVSS 6.7 · Published 2026-07-23

Vendors: Axiomthemes.

Executive brief

A security flaw exists in the QuickCal appointment booking plugin for WordPress, which is used to manage schedules and client bookings. Users with 'Booking Agent' privileges can bypass intended restrictions to perform actions or access data they should not be authorized to see. This could lead to unauthorized modification of calendar data or exposure of sensitive booking information.

Technical details

A broken access control vulnerability (CWE-862: Missing Authorization) exists in the QuickCal plugin for WordPress through version 1.0.16. The flaw resides in the handling of booking agent permissions, where the application fails to properly validate authorization for certain functions. An attacker with high-level privileges (specifically the 'Booking Agent' role) can exploit this over a network without user interaction to gain unauthorized access to data or modify settings. As of the advisory date, no official patch has been released.

Affected products

  • AxiomThemes / Pixel Makers Creative INC. QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16

Timeline

  • 2025-11-21: other: Vulnerability reported by researcher Phat RiO
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset

References