Broken Access Control in QuickCal Appointment Booking Calendar for WordPress
CVE-2026-27377
6.7MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 July 2026
What is CVE-2026-27377?
The QuickCal - Appointment Booking Calendar for WordPress, specifically versions up to 1.0.16, suffers from a broken access control vulnerability that allows unauthorized users to gain access to functions and data restricted to authenticated users. This flaw can potentially enable attackers to manipulate user accounts or access sensitive information. Website administrators should update to the latest version to mitigate this risk and ensure site security.
Affected Version(s)
QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16