WP Clinic
Log in Sign up

CVE · Medium

CVE-2024-13821 — Booking Calendar [booking] < 10.10.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13821 Booking Calendar [booking] < 10.10.1 Improper Authorization Medium 5.3 < 10.10.1 10.10.1 2025-02-11

CVE-2024-13821

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.