CVE-2024-13821
The Booking Calendar plugin contains a vulnerability in versions up to 10.10 that allows unauthenticated users to modify their confirmed bookings without needing to verify their identity again. Because the plugin fails to implement proper verification checks when booking changes are requested, attackers can alter approved reservations even though they lack authentication. This flaw exposes bookings to unauthorized manipulation after the initial confirmation stage.
Based on public CVE data (MITRE/NVD).