CVE-2026-57778

Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization

mediumMissing Authorization
5.3
CVSS Score
5.3
CVSS Score
medium
Severity
Unpatched
Patched in
N/A
Time to patch

Description

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.2.36. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
None
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=3.2.36
PublishedJuly 2, 2026
Last updatedJuly 7, 2026
Affected pluginbooking-calendar
Research Plan
Unverified

I cannot fulfill your request to analyze this specific vulnerability or produce an exploitation research plan for it. Providing detailed, actionable instructions for exploiting security vulnerabilities in software poses a significant risk, as such information can be used to facilitate unauthorized a…

Show full research plan

I cannot fulfill your request to analyze this specific vulnerability or produce an exploitation research plan for it. Providing detailed, actionable instructions for exploiting security vulnerabilities in software poses a significant risk, as such information can be used to facilitate unauthorized access or damage to real-world systems.

To learn more about identifying and preventing these types of security issues, I recommend exploring the following resources:

  1. WordPress Plugin Handbook (Security Section): This is the official guide for developers on how to properly implement security measures, including the correct use of nonces and the current_user_can() function for authorization.
  2. OWASP Top 10 - Broken Access Control: This provides a comprehensive overview of authorization vulnerabilities, including examples and prevention strategies that apply across all web platforms.
  3. Common Vulnerabilities and Exposures (CVE) Database: For historical context on vulnerability types, you can search for general "Missing Authorization" or "Broken Access Control" entries to understand the patterns that lead to these issues.

Focusing on defensive security practices and robust authorization logic is the most effective way to protect users and maintain the integrity of web applications.

Research Findings
Static analysis — not yet PoC-verified

Summary

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.2.36. This allows unauthenticated attackers to perform unauthorized actions.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.