The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain. This allows an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier. The affected product is used for managing bookings and events on WordPress sites. The [truncated]
LOWBooking for Appointments and Events CalendarCVE published 2026-08-29
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment.
LOWBooking for Appointments and Events CalendarCVE published 2026-08-10
The Booking for Appointments and Events Calendar WordPress plugin before version 9.7 has a vulnerability that allows any employee with an Employee Panel login to read and modify customer personal data by enumerating sequential identifiers. This issue affects organizations using the plugin, particularly those with multiple employees accessing customer data. The vulnerability class is related to insufficien [truncated]