CVE-2025-67574
Description
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.30.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Booking calendar plugin ≤3.2.30 allows unauthenticated exploitation of incorrectly configured access controls.
Overview
The Booking calendar, Appointment Booking System plugin for WordPress (versions ≤3.2.30) contains a missing authorization vulnerability. The issue arises from incorrect configuration of access control security levels, allowing attackers to bypass intended permission checks [1].
Exploitation
An attacker can exploit this broken access control without requiring authentication, as the plugin fails to properly verify user capabilities before granting access to certain functions or data. The vulnerability is classified under the 'Exploiting Incorrectly Configured Access Control Security Levels' category, indicating a systemic misconfiguration rather than a single missing check [1].
Impact
Successful exploitation could allow an unprivileged attacker to perform actions or access resources that should be restricted. While the CVSS score is 5.3 (Medium), the practical risk is elevated because this type of vulnerability is commonly used in mass-exploit campaigns targeting thousands of websites [1].
Mitigation
The vendor has released version 3.2.31 which resolves the issue. Users are advised to update immediately. Patchstack users can enable auto-updates for affected plugins. No workarounds are provided if updating is not possible [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=3.2.30
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.