Authorization Bypass in Booking Calendar Plugin for WordPress
CVE-2026-8840

5.3MEDIUM

What is CVE-2026-8840?

The Booking Calendar, Appointment Booking System plugin for WordPress is susceptible to an authorization bypass, enabling unauthorized users to execute actions without proper validation. This exploitation allows unauthenticated attackers to manipulate payment status, mark reservations as paid or completed, cancel legitimate payments, and send booking emails by directly writing to the payments table. Notably, while auto-approval of reservations can occur if the 'enable_psuccess_approval' site option is turned on, the vulnerability allows for various forms of manipulation irrespective of this setting.

Affected Version(s)

Booking calendar, Appointment Booking System 0 <= 3.2.36

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Raihan Adi Arba
.