CVE-2025-64261: WordPress Appointment Booking Calendar plugin <= 1.3.95 - Broken Access Control vulnerability
Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.95.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64261?
CVE-2025-64261 is classified as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-64261?
To fix CVE-2025-64261, update the Appointment Booking Calendar plugin to the latest version available.
What causes CVE-2025-64261?
CVE-2025-64261 is caused by missing authorization checks that allow for improperly configured access control.
What versions are affected by CVE-2025-64261?
CVE-2025-64261 affects all versions of Appointment Booking Calendar from n/a through version 1.3.95.
Who is impacted by CVE-2025-64261?
Users of the Appointment Booking Calendar plugin on WordPress who are running version 1.3.95 or lower are impacted by CVE-2025-64261.