The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to arbitrarily confirm bookings and bypass payment requirements via the 'dex_bccf_ipn' parameter.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codepeople
Codepeople booking Calendar Contact Form Wordpress Wordpress wordpress |
|
| Vendors & Products |
Codepeople
Codepeople booking Calendar Contact Form Wordpress Wordpress wordpress |
Sat, 22 Nov 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to arbitrarily confirm bookings and bypass payment requirements via the 'dex_bccf_ipn' parameter. | |
| Title | Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-22T08:30:29.623Z
Updated: 2025-11-24T19:35:04.659Z
Reserved: 2025-11-17T15:18:42.968Z
Link: CVE-2025-13318
Updated: 2025-11-24T19:35:00.526Z
Status : Received
Published: 2025-11-22T09:15:42.987
Modified: 2025-11-22T09:15:42.987
Link: CVE-2025-13318
No data.
ReportizFlow