Missing Authorization in Appointment Booking Calendar Plugin for WordPress
CVE-2025-13317
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 November 2025
What is CVE-2025-13317?
The Appointment Booking Calendar plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit an endpoint responsible for booking processing. This endpoint, cpabc_appointments_check_IPN_verification, fails to validate the origin and authenticity of payment notifications. As a result, attackers can manipulate bookings and add them directly to the calendar, sending unauthorized notifications to both administrators and customers, which can disrupt normal operations and lead to a compromised user experience.
Affected Version(s)
Appointment Booking Calendar * <= 1.3.96