Missing Authorization Vulnerability in wpdevart Booking Calendar from WordPress
CVE-2026-57778
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 July 2026
What is CVE-2026-57778?
The wpdevart Booking Calendar, Appointment Booking System is susceptible to a missing authorization vulnerability. This flaw stems from incorrectly configured access control security levels, which may allow unauthorized access to sensitive features and data within the application. It impacts users operating versions from n/a up to and including 3.2.36, potentially exposing them to risks associated with unauthorized actions.
Affected Version(s)
Booking calendar, Appointment Booking System 0 <= 3.2.36