CVE-2023-24407

Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpdevart:booking_calendar:*:*:*:*:*:wordpress:*:*

History

28 Apr 2026, 19:19

Type Values Removed Values Added
Summary (en) Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.3. (en) Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
References
  • {'url': 'https://patchstack.com/database/Wordpress/Plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-broken-access-control?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/wordpress/plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-broken-access-control?_s_id=cve - Third Party Advisory

23 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3. (en) Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.3.
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-broken-access-control?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-broken-access-control?_s_id=cve - Third Party Advisory

21 Mar 2025, 18:45

Type Values Removed Values Added
First Time Wpdevart
Wpdevart booking Calendar
References () https://patchstack.com/database/wordpress/plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-broken-access-control?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/booking-calendar/vulnerability/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-broken-access-control?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:wpdevart:booking_calendar:*:*:*:*:*:wordpress:*:*
Summary
  • (es) La vulnerabilidad de autorización faltante en WpDevArt Booking calendar, Appointment Booking System permite explotar los niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Booking calendar, Appointment Booking System: desde n/a hasta 3.2.3.

09 Dec 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-09 13:15

Updated : 2026-04-28 19:19


NVD link : CVE-2023-24407

Mitre link : CVE-2023-24407

CVE.ORG link : CVE-2023-24407


JSON object : View

Products Affected

wpdevart

  • booking_calendar
CWE
CWE-862

Missing Authorization