Medium severity5.3NVD Advisory· Published Apr 28, 2017· Updated May 13, 2026
CVE-2017-2150
CVE-2017-2150
Description
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.
Affected products
2- cpe:2.3:a:booking_calendar_project:booking_calendar:*:*:*:*:*:wordpress:*:*Range: <=7.0
- wpdevelop/Booking Calendarv5Range: version 7.0 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN18739672/index.htmlnvdThird Party AdvisoryVDB Entry
- wpbookingcalendar.com/changelog/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.