Booking Calendar
cpe:2.3:a:booking_calendar_project:booking_calendar:*:*:*:*:wordpress:*:*
- <= 10.14.13
A vulnerability in the Booking Calendar plugin for WordPress allows unauthorized data access. This issue arises from a missing capability check in the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function, affecting all versions up to and including 10.14.13. As a result, unauthenticated attackers can retrieve booking details, including customer names, phone numbers, and email addresses.
Exploitation of this vulnerability could lead to unauthorized access to sensitive booking information, including customer contact details.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.