Race Condition Vulnerability in WPdevelop Booking Calendar Plugin
CVE-2026-39601

3.7LOW

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 October 2026

What is CVE-2026-39601?

A race condition vulnerability exists in the WPdevelop Booking Calendar plugin, allowing attackers to exploit concurrent execution paths due to improper synchronization. This flaw can lead to unintended behavior within the booking system, potentially compromising user actions and interactions. Users of Booking Calendar versions from n/a to 11.8.4 are particularly affected by this issue, highlighting the need for prompt updates and security measures.

Affected Version(s)

Booking Calendar 0 <= 11.8.4

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.