PT-2025-47827 · WordPress · Appointment Booking Calendar
Published
2025-11-22
·
Updated
2025-11-22
·
CVE-2025-13317
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Appointment Booking Calendar versions prior to 1.3.97
Description
The Appointment Booking Calendar plugin for WordPress is affected by a missing authorization issue. The plugin exposes an unauthenticated booking processing endpoint,
/cpabc appointments check IPN verification, which does not verify the origin or authenticity of attacker-supplied payment notifications and lacks proper authorization checks. This allows unauthenticated attackers to confirm bookings and insert them into the live calendar by manipulating the cpabc ipncheck parameter, potentially triggering administrative and customer notification emails and disrupting operations.Recommendations
Update Appointment Booking Calendar to version 1.3.97 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appointment Booking Calendar