CVE-2025-13318: Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the dexbccfcheckIPNverification function. This makes it possible for unauthenticated attackers to arbitrarily confirm bookings and bypass payment requirements via the 'dexbccfipn' parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13318?
CVE-2025-13318 has a medium severity due to the lack of authorization checks in the affected plugin.
How do I fix CVE-2025-13318?
To fix CVE-2025-13318, upgrade the Booking Calendar Contact Form plugin to version 1.2.61 or later.
What is the impact of CVE-2025-13318?
The impact of CVE-2025-13318 includes potential unauthorized access to sensitive information due to missing authorization checks.
Which versions of the Booking Calendar Contact Form are affected by CVE-2025-13318?
All versions of the Booking Calendar Contact Form plugin up to and including version 1.2.60 are affected by CVE-2025-13318.
Who is the vendor responsible for CVE-2025-13318?
The vendor responsible for CVE-2025-13318 is Booking Calendar, the developer of the Contact Form plugin.