Impact
The Booking for Appointments and Events Calendar WordPress plugin before version 2.4.9 does not enforce authentication or a valid request token when executing the post‑booking action chain. An unauthenticated user can supply a booking identifier and trigger the chain that sends booking notifications and fires configured integration callbacks such as email alerts or external API calls. This flaw is an authorization bypass identified as CWE‑862 and can be used to generate unwanted notifications, abuse integrated services, or potentially cause resource exhaustion.
Affected Systems
WordPress sites that have the Booking for Appointments and Events Calendar plugin installed with a version older than 2.4.9 are vulnerable. The plugin vendor is listed as Unknown: Booking for Appointments and Events Calendar. No other products or vendor products are indicated in the CVE data, so only sites using this specific plugin version are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only knowledge or enumeration of a valid booking identifier, with no authentication needed. Because the attack path is straightforward and the CVE description notes no authentication or request token requirement, an attacker can trigger notifications or external callbacks. The potential impact of such actions (for example, spam, phishing, or denial‑of‑service via mail or API resource exhaustion) is inferred from the nature of the notifications, as the description does not explicitly confirm these outcomes.
OpenCVE Enrichment