Booking Calendar Contact Form <= 1.2.60 - Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter
2025-11-21 19:35
Md. Moniruzzaman Prodhan (NomanProdhan)Strategic Overview
StatusPatched in 1.2.61
Affected PluginBooking Calendar Contact Form
Affected Version
<= 1.2.60CVSS5.3Medium
CVE
CVE-2025-13318Vulnerability Overview
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to arbitrarily confirm bookings and bypass payment requirements via the 'dex_bccf_ipn' parameter.
Technical Analysis
REMEDIATION: Update to version 1.2.61, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C