PT-2026-34857 · WordPress · Booking-Calendar-Contact-Form
Published
2026-04-24
·
Updated
2026-04-25
·
CVE-2026-6810
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Booking Calendar Contact Form versions prior to 1.2.64
Description
The Booking Calendar Contact Form plugin for WordPress contains an Insecure Direct Object Reference (IDOR) issue—a flaw where an application provides direct access to objects based on user-supplied input. The problem exists in the
dex bccf admin int calendar list.inc.php file due to missing validation on a user-controlled key. This allows authenticated attackers with Subscriber-level access or higher to take over other users' calendars and view associated user data.Recommendations
Update the plugin to a version later than 1.2.63.
As a temporary workaround, restrict access to the
dex bccf admin int calendar list.inc.php file to minimize the risk of exploitation.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Booking-Calendar-Contact-Form