Description
The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update-appointment REST API endpoint in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to modify the status of any appointment.
Problem types
Product status
* (semver)
Timeline
| 2026-02-13: | Disclosed |
Credits
MD. TAREQ AHAMED JONY
References
www.wordfence.com/...-9e91-4ed5-9749-4a14e8180e71?source=cve
plugins.trac.wordpress.org/...ler/appointment-controller.php
plugins.trac.wordpress.org/...ler/appointment-controller.php