cleantalk
Vulnerabilities and Security Researches

WP Booking Calendar, CVE-2024-13821

CVE, Research URL

CVE-2024-13821

Application

WP Booking Calendar

Published on
Feb 12, 2025
Research Description
The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.
Affected versions
Min -, max 10.10.1.
Status
vulnerable