Unauthorized Data Modification in Booktics - Booking Calendar for Appointments and Service Businesses by WordPress
CVE-2026-11446

5.3MEDIUM

What is CVE-2026-11446?

The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress has a vulnerability allowing unauthorized modifications of customer data. The issue arises from the create_order_permission() function, which lacks proper authentication checks. This flaw permits unauthenticated attackers to overwrite the contact details, such as name and phone number, of any existing customer if they know the email address. This unauthorized access can lead to the alteration of critical customer information, impacting downstream communications like automated reminders and customer relationship management (CRM) data.

Affected Version(s)

Booktics – Appointment Booking Calendar for Service Businesses 0 <= 1.0.23

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

revblock
.