Broken Access Control in QuickCal Appointment Booking Calendar for WordPress
CVE-2026-27377

6.7MEDIUM

What is CVE-2026-27377?

The QuickCal - Appointment Booking Calendar for WordPress, specifically versions up to 1.0.16, suffers from a broken access control vulnerability that allows unauthorized users to gain access to functions and data restricted to authenticated users. This flaw can potentially enable attackers to manipulate user accounts or access sensitive information. Website administrators should update to the latest version to mitigate this risk and ensure site security.

Affected Version(s)

QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO | Patchstack Bug Bounty Program
.