CyberRota Analysis
AI-GeneratedThe Booking for Appointments and Events Calendar plugin for WordPress versions prior to 2.4.9 is vulnerable due to a lack of authentication and request token validation, enabling unauthenticated users to exploit the post-booking action chain. This vulnerability allows attackers to trigger booking notifications and integration callbacks by simply enumerating booking identifiers, potentially leading to unauthorized access and information disclosure. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier.