Impact
The Booking Calendar plugin version 11.7 and earlier contains a flaw that allows any user, even those not logged in, to bypass internal permission checks. Attackers can exploit this to carry out privileged operations such as creating, editing, or deleting appointments and potentially accessing sensitive booking data. The vulnerability is classified as a CWE‑862 type broken access control weakness and carries a CVSS score of 5.3, indicating a moderate risk to confidentiality and integrity.
Affected Systems
This issue affects the WordPress plugin Booking Calendar from the vendor wpdevelop. Any WordPress site running the plugin through version 11.7 or earlier is at risk; newer releases are not impacted.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium severity range, and no EPSS data is available at this time. The vulnerability is not listed in CISA KEV, so there is no public record of a known exploit. Based on the description, the likely attack vector is remote exploitation via HTTP requests directed at plugin endpoints or API routes that improperly enforce access checks. If an attacker can reach a site running the affected plugin, they can assume privileged actions without authentication.
OpenCVE Enrichment