Executive brief
The wpdevart Booking calendar plugin for WordPress, which is used to manage appointments and schedules, contains a security flaw in its access control settings. This vulnerability could allow an unauthorized person to perform actions that should be restricted to administrators or specific staff members. While the impact is currently rated as medium, it could potentially lead to unauthorized changes in the booking system's configuration or data.
Technical details
A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the wpdevart Booking calendar, Appointment Booking System plugin for WordPress. The flaw stems from incorrectly configured access control security levels within the plugin's functions. An unauthenticated remote attacker can exploit this to execute actions that should require higher privileges. The vulnerability affects all versions up to and including 3.2.36. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates from the developer.
Affected products
- wpdevart Booking calendar, Appointment Booking System (booking-calendar) n/a through 3.2.36
Timeline
- 2026-01-21: disclosed: Reported by Nabil Irawan
- 2026-07-02: advisory: Initial advisory published by Patchstack
- 2026-07-13: advisory: CVE published to NVD dataset