Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6449

Опубликовано: 02 мая 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint.

EPSS

Процентиль: 38%
0.00458
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 5.3
github
3 месяца назад

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting' status. This makes it possible for unauthenticated attackers to approve any booking that is in 'waiting' status by sending a crafted request to the publicly-accessible admin-ajax endpoint.

EPSS

Процентиль: 38%
0.00458
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285