๐Ÿ” CVE Alert

CVE-2026-8840

MEDIUM 5.3

Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary reservations as paid or completed, cancel legitimate payments, auto-approve reservations, and trigger transactional booking emails by writing attacker-supplied payment status and transaction data directly into the payments table. The auto-approval of reservations is only triggered when the 'enable_psuccess_approval' site option is enabled, but payment status manipulation and email dispatch are exploitable regardless of that setting.

CWE CWE-862
Vendor wpdevart
Product booking calendar, appointment booking system
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for wpdevart booking calendar, appointment booking system

Be the first to know when new medium vulnerabilities affecting wpdevart booking calendar, appointment booking system are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

wpdevart / Booking calendar, Appointment Booking System
0 โ‰ค 3.2.36

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/88409bb0-5cb0-4f63-b8f0-d72f54fa17b0?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking-calendar/tags/3.2.36/admin/controllers/Payment.php#L26 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking-calendar/tags/3.2.36/admin/controllers/Payment.php#L16 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking-calendar/tags/3.2.36/booking_calendar.php#L578 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking-calendar/tags/3.2.36/booking_calendar.php#L131 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking-calendar/tags/3.2.35/admin/controllers/Payment.php#L26 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking-calendar/tags/3.2.35/admin/controllers/Payment.php#L16 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking-calendar/tags/3.2.35/booking_calendar.php#L578 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking-calendar/tags/3.2.35/booking_calendar.php#L131

Credits

Raihan Adi Arba