Executive brief
The Court Reservation plugin for WordPress, used for managing sports court bookings, contains a security flaw in its access control system. This vulnerability allows unauthorized individuals to bypass intended security levels and potentially modify booking data or system settings. Such an exploit could disrupt business operations by allowing unauthorized changes to court schedules or reservations.
Technical details
A Missing Authorization vulnerability (CWE-862) exists in the webmuehle Court Reservation plugin for WordPress through version 1.10.11. The issue stems from incorrectly configured access control security levels, where the application fails to perform sufficient authorization checks on certain functions. An unauthenticated remote attacker can exploit this flaw to execute actions that should be restricted to higher-privileged users. Depending on the specific function targeted, this could result in unauthorized data modification or integrity loss. As of the advisory date, no official patch has been confirmed.
Affected products
- webmuehle Court Reservation <= 1.10.11
Timeline
- 2026-01-20: other: Vulnerability reported by researcher Nabil Irawan
- 2026-02-19: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD