PT-2025-47827 · WordPress · Appointment Booking Calendar

Published

2025-11-22

·

Updated

2025-11-22

·

CVE-2025-13317

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Appointment Booking Calendar versions prior to 1.3.97
Description The Appointment Booking Calendar plugin for WordPress is affected by a missing authorization issue. The plugin exposes an unauthenticated booking processing endpoint, /cpabc appointments check IPN verification, which does not verify the origin or authenticity of attacker-supplied payment notifications and lacks proper authorization checks. This allows unauthenticated attackers to confirm bookings and insert them into the live calendar by manipulating the cpabc ipncheck parameter, potentially triggering administrative and customer notification emails and disrupting operations.
Recommendations Update Appointment Booking Calendar to version 1.3.97 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13317

Affected Products

Appointment Booking Calendar