Executive brief
The Booking calendar plugin, a WordPress tool for managing appointment bookings and payments, fails to properly verify user permissions. This allows unauthenticated attackers to manipulate payment records directly, marking reservations as paid or cancelled without authorization, and triggering booking confirmation emails to customers. In configurations with auto-approval enabled, attackers can also automatically approve reservations, potentially leading to fraudulent bookings or revenue loss.
Technical details
The plugin contains an authorization bypass vulnerability in its payment handling functions due to missing or insufficient permission checks before processing payment-related actions. Unauthenticated attackers can directly write arbitrary payment status and transaction data to the payments table without authentication, allowing them to manipulate reservation states, cancel payments, and trigger transactional emails. The auto-approval of reservations occurs only when the 'enable_psuccess_approval' site option is enabled, but payment manipulation and email dispatch are exploitable unconditionally. The root cause is in the Payment.php controller, which does not properly validate user authorization before processing payment updates.
Affected products
- WordPress Booking calendar up to and including 3.2.36
Timeline
- 2026-08-15: disclosed