Booking Calendar Contact Form Missing Authorization Vulnerability Allowing Arbitrary Booking Confirmation

Vulnerability

A vulnerability exists in the Booking Calendar Contact Form plugin for WordPress, in all versions through 1.2.60. The issue is a missing authorization check in the 'dex_bccf_check_IPN_verification' function, which allows unauthenticated users to bypass payment requirements and arbitrarily confirm bookings by manipulating the 'dex_bccf_ipn' parameter.

Impact

Exploitation of this vulnerability allows for unauthorized booking confirmations, bypassing payment requirements.

Remediation

Users can update to version 1.2.61 or a newer patched version to address this vulnerability.

Added: Nov 22, 2025, 9:18 AM
Updated: Nov 22, 2025, 9:18 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
8.2
remediation
7.7
relevance
1.1
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.