Executive brief
Booking Calendar is a WordPress plugin used to manage appointment and event scheduling on websites. An unauthenticated attacker can bypass access controls to view or perform actions they should not be permitted to access, such as viewing bookings or calendar data belonging to other users or administrators.
Technical details
This vulnerability is a broken access control flaw in Booking Calendar plugin versions 11.7 and earlier. The vulnerability allows unauthenticated users to access restricted pages and perform unauthorized actions without proper authentication checks. The root cause is insufficient authorization validation on sensitive endpoints. An attacker can exploit this over the network by directly accessing affected functionality without credentials to view or manipulate booking and calendar data. The vulnerability has been patched in version 11.8 and later.
Affected products
- Booking Calendar Booking Calendar <=11.7
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in version 11.8