Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51755 | The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved. |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 25 Feb 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpbookingcalendar
Wpbookingcalendar booking Calendar |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:wpbookingcalendar:booking_calendar:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpbookingcalendar
Wpbookingcalendar booking Calendar |
Wed, 12 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Feb 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved. | |
| Title | WP Booking Calendar <= 10.10 - Unauthenticated Post-Confirmation Booking Manipulation | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:05:37.614Z
Reserved: 2025-01-31T20:09:08.849Z
Link: CVE-2024-13821
Updated: 2025-02-12T14:56:19.482Z
Status : Analyzed
Published: 2025-02-12T08:15:08.660
Modified: 2025-02-25T19:37:29.223
Link: CVE-2024-13821
No data.
OpenCVE Enrichment
No data.
EUVD