Impact
The Booking for Appointments and Events Calendar WordPress plugin versions before 9.8.1 accepts booking requests that are unauthenticated and blindly trusts the payment gateway name supplied in the request. The plugin does not verify that a payment has actually been processed, letting an attacker create bookings that appear fully paid without any money being collected. This flaw (CWE‑284) permits the production of illegitimate paid appointments and events that can be invoiced to customers or recorded as revenue.
Affected Systems
WordPress sites running the Booking for Appointments and Events Calendar plugin prior to version 9.8.1, including all supported releases from 9.0 through 9.7.x, are affected. The vulnerability is present wherever the post-payment verification step is missing, regardless of whether a payment gateway has been configured on the site.
Risk and Exploitability
The vulnerability is remotely exploitable without any authentication. A CVSS score of 5.3 indicates moderate severity, while the EPSS score of <1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, meaning no confirmed active exploitation is reported. Nonetheless, the ability to create unlimited fraudulent paid bookings could lead to significant financial loss and reputational damage for affected organisations. Attacks can be launched simply by sending booking requests that name any payment gateway, including unconfigured ones, exploiting a broken access control.
OpenCVE Enrichment