Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qfjv-r2q6-x287

Опубликовано: 24 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to takeover other user's calendars and view user data associated with the calendar.

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to takeover other user's calendars and view user data associated with the calendar.

EPSS

Процентиль: 26%
0.0033
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to takeover other user's calendars and view user data associated with the calendar.

EPSS

Процентиль: 26%
0.0033
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639