Impact
The Booking for Appointments and Events Calendar WordPress plugin versions prior to 9.8.1 accepts booking requests without requiring authentication and blindly trusts the payment gateway name supplied in the request. The plugin does not verify that a payment has actually been processed, permitting an attacker to create bookings that appear fully paid without any money being collected. This flaw combines improper input validation (CWE‑20) with broken access control (CWE‑284), enabling the production of illegitimate paid appointments and events that can be invoiced to customers or recorded as revenue.
Affected Systems
WordPress installations that have the Booking for Appointments and Events Calendar plugin deployed in any release before 9.8.1 are affected. This includes all supported major releases from 9.0 through 9.7.x, where the post‑payment verification step is missing. Sites running any of those versions are susceptible to the payment bypass regardless of whether the site has configured the named payment gateway.
Risk and Exploitability
The vulnerability is remotely exploitable without authentication; an attacker can easily fabricate requests that claim a paid status. The CVSS score of 5.3 indicates moderate severity, but the EPSS score of < 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, so no confirmed active exploitation is reported. Nonetheless, the ability to create unlimited fraudulent paid bookings can cause significant financial loss and reputational damage to affected organisations. Until the plugin is updated, the risk remains present for all vulnerable sites.
OpenCVE Enrichment