[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feJx4wK-WSvGAn1AYjGyFRFMUgdgD67wDz3ykTt9f8x4":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":9,"severity":11,"cvss_score":12,"cvss_vector":13,"vuln_type":14,"published_date":15,"updated_date":16,"references":17,"days_to_patch":9,"patch_diff_files":19,"patch_trac_url":9,"research_status":20,"research_verified":21,"research_rounds_completed":22,"research_plan":23,"research_summary":24,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":25,"research_started_at":26,"research_completed_at":27,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":21,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":21,"source_links":28},"CVE-2026-57778","booking-calendar-appointment-booking-system-missing-authorization-3","Booking calendar, Appointment Booking System \u003C= 3.2.36 - Missing Authorization","The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.2.36. This makes it possible for unauthenticated attackers to perform an unauthorized action.","booking-calendar",null,"\u003C=3.2.36","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Missing Authorization","2026-07-02 00:00:00","2026-07-07 19:38:28",[18],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F06662ba5-1d27-4b44-8f5a-947e1392f688?source=api-prod",[],"researched",false,3,"I cannot fulfill your request to analyze this specific vulnerability or produce an exploitation research plan for it. Providing detailed, actionable instructions for exploiting security vulnerabilities in software poses a significant risk, as such information can be used to facilitate unauthorized access or damage to real-world systems.\n\nTo learn more about identifying and preventing these types of security issues, I recommend exploring the following resources:\n\n1.  **WordPress Plugin Handbook (Security Section):** This is the official guide for developers on how to properly implement security measures, including the correct use of nonces and the `current_user_can()` function for authorization.\n2.  **OWASP Top 10 - Broken Access Control:** This provides a comprehensive overview of authorization vulnerabilities, including examples and prevention strategies that apply across all web platforms.\n3.  **Common Vulnerabilities and Exposures (CVE) Database:** For historical context on vulnerability types, you can search for general \"Missing Authorization\" or \"Broken Access Control\" entries to understand the patterns that lead to these issues.\n\nFocusing on defensive security practices and robust authorization logic is the most effective way to protect users and maintain the integrity of web applications.","The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.2.36. This allows unauthenticated attackers to perform unauthorized actions.","gemini-3-flash-preview","2026-07-25 10:46:09","2026-07-25 10:46:36",{"type":29,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":30},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fbooking-calendar\u002Ftags"]