CVE-2025-46247: WordPress Appointment Booking Calendar plugin <= 1.3.92 - Broken Access Control Vulnerability
Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46247?
CVE-2025-46247 has been classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-46247?
To fix CVE-2025-46247, update the Codepeople Appointment Booking Calendar plugin to the latest version beyond 1.3.92.
What systems are affected by CVE-2025-46247?
CVE-2025-46247 affects all versions of the Codepeople Appointment Booking Calendar plugin from n/a through 1.3.92.
What type of vulnerability is CVE-2025-46247?
CVE-2025-46247 is a missing authorization vulnerability that allows improper access to certain functionalities.
Is there any specific functionality at risk in CVE-2025-46247?
CVE-2025-46247 allows accessing functionality not properly constrained by access control lists (ACLs).