PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77704 Booking for Appointments and Events Calendar CVE debrief

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment.

Vendor
Booking for Appointments and Events Calendar
Product
Booking for Appointments and Events Calendar
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-29
Original CVE updated
2026-08-29
Advisory published
2026-08-29
Advisory updated
2026-08-29

Who should care

Administrators and users of the Booking for Appointments and Events Calendar WordPress plugin should be aware of this vulnerability and take necessary actions to mitigate it. This includes updating the plugin to version 2.4.9 or later and reviewing user capabilities and appointment status changes. Security teams and vulnerability management teams should also review the affected plugin and implement compensating controls if necessary. Operators of shared appointment schedules should verify that users do not have arbitrary status change capabilities on appointments they are booked on. Platform administrators may need to review logs for suspicious appointment status changes. Vulnerability management teams should prioritize patching or mitigating this vulnerability, as it could allow unauthorized changes to appointment statuses, potentially impacting multiple users and appointments. Security teams should monitor for potential exploitation attempts and implement additional logging and monitoring for exposed systems. Asset inventory and configuration management teams may need to verify plugin versions and user roles to ensure proper mitigation. Change management and incident response teams should be prepared to respond to potential exploitation incidents and have rollback procedures in place if necessary. Source tracking and threat intelligence teams should monitor for potential exploitation attempts and update their threat models accordingly. Compensating controls, such as additional logging and monitoring, may be necessary for exposed systems while remediation is scheduled and verified. Rollback change windows and source tracking may be necessary to ensure proper mitigation and to detect potential exploitation attempts. Monitoring and detection teams should review relevant logs for exposed assets that need extra review. Exceptions and retesting of remediated assets should be tracked, and the item should only be closed after evidence of proper mitigation is documented. This may involve collaboration between security, IT, and development teams to ensure comprehensive mitigation and to prevent potential exploitation. In addition, review of compensating controls for the

Technical summary

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not properly check user capabilities, allowing customers to change appointment statuses arbitrarily. This could lead to unauthorized changes to appointment statuses, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment. Technical details indicate a capability check bypass, potentially allowing low-privileged users to modify appointment statuses.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability, as it could allow unauthorized changes to appointment statuses.

Recommended defensive actions

  • Patch or upgrade the Booking for Appointments and Events Calendar WordPress plugin to version 2.4.9 or later.
  • Implement compensating controls, such as monitoring and logging, to detect potential unauthorized changes to appointment statuses.
  • Verify that users do not have arbitrary status change capabilities on appointments they are booked on.
  • Review logs for suspicious appointment status changes.
  • Monitor for potential exploitation attempts and implement additional logging and monitoring for exposed systems.
  • Verify plugin versions and user roles to ensure proper mitigation.
  • Track exceptions and retest remediated assets to ensure comprehensive mitigation.

Evidence notes

The evidence for this vulnerability is limited. Official records indicate a capability check issue in the Booking for Appointments and Events Calendar WordPress plugin before version 2.4.9. Defenders should verify the plugin version and user capabilities to confirm exposure. Additional review of user booking status changes and appointment approvals may be necessary.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77704 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77704

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77704 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77704

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.