VYPR
Medium severity5.3NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-67574

CVE-2025-67574

Description

Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.30.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Booking calendar plugin ≤3.2.30 allows unauthenticated exploitation of incorrectly configured access controls.

Overview

The Booking calendar, Appointment Booking System plugin for WordPress (versions ≤3.2.30) contains a missing authorization vulnerability. The issue arises from incorrect configuration of access control security levels, allowing attackers to bypass intended permission checks [1].

Exploitation

An attacker can exploit this broken access control without requiring authentication, as the plugin fails to properly verify user capabilities before granting access to certain functions or data. The vulnerability is classified under the 'Exploiting Incorrectly Configured Access Control Security Levels' category, indicating a systemic misconfiguration rather than a single missing check [1].

Impact

Successful exploitation could allow an unprivileged attacker to perform actions or access resources that should be restricted. While the CVSS score is 5.3 (Medium), the practical risk is elevated because this type of vulnerability is commonly used in mass-exploit campaigns targeting thousands of websites [1].

Mitigation

The vendor has released version 3.2.31 which resolves the issue. Users are advised to update immediately. Patchstack users can enable auto-updates for affected plugins. No workarounds are provided if updating is not possible [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.