Missing Authorization in wpdevart Booking Calendar Affects Appointment Booking System
CVE-2025-67574

5.3MEDIUM

What is CVE-2025-67574?

A missing authorization vulnerability has been discovered in the wpdevart Booking Calendar, specifically affecting the Appointment Booking System. This vulnerability allows attackers to exploit incorrectly configured access control levels, enabling unauthorized access to sensitive functionalities. The issue impacts versions up to and including 3.2.30 of the product, potentially compromising user data and system integrity.

Affected Version(s)

Booking calendar, Appointment Booking System <= n/a

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter | Patchstack Bug Bounty Program
.