PT-2025-47834 · WordPress · Booking-Calendar-Contact-Form

Published

2025-11-22

·

Updated

2025-11-22

·

CVE-2025-13318

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Booking Calendar Contact Form plugin for WordPress versions prior to 1.2.61
Description The plugin lacks proper authorization checks and payment verification. This allows unauthenticated attackers to confirm bookings and bypass payment requirements. The issue is present in the dex bccf check IPN verification function and is triggered through the dex bccf ipn parameter.
Recommendations Update the Booking Calendar Contact Form plugin to version 1.2.61 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13318

Affected Products

Booking-Calendar-Contact-Form