PT-2026-20474 · WordPress · Booking Calendar

Poystick

+1

·

Publicado

2026-02-18

·

Atualizado

2026-02-18

·

CVE-2026-2230

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Booking Calendar versions prior to 10.14.15
Description The Booking Calendar plugin for WordPress is susceptible to an Insecure Direct Object Reference issue. This flaw stems from inadequate validation of a user-controlled key within the handle ajax save function. Authenticated attackers possessing Subscriber-level access or higher, and with booking permissions granted by an Administrator, can potentially modify other users' plugin settings, such as booking calendar display options. Successful exploitation can disrupt the booking calendar functionality for targeted users.
Recommendations Update Booking Calendar to version 10.14.15 or later.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2230

Produtos afetados

Booking Calendar