First published: Wed Feb 12 2025(Updated: )
The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Booking Calendar | <=10.10 | |
Booking Calendar | <10.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13821 is considered a moderate severity vulnerability due to unauthenticated booking manipulation.
To fix CVE-2024-13821, update the WP Booking Calendar plugin to version 10.11 or later.
CVE-2024-13821 affects all versions of the WP Booking Calendar plugin up to and including version 10.10.
CVE-2024-13821 is an unauthenticated post-confirmation booking manipulation vulnerability.
There is no official workaround for CVE-2024-13821; updating to the latest version is necessary.