5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to arbitrarily confirm bookings and bypass payment requirements via the 'dex_bccf_ipn' parameter.
Basic Information
ID
CVE-2025-13318
Source
Wordfence
Published
Nov 22, 2025 at 08:30
Affected Product
Vendor
codepeople
Product
Booking Calendar Contact Form
Version
*
Affected Versions
codepeople Booking Calendar Contact Form *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/83b0ae2c-6b08-4b71-a728-c60722ec20c7
- plugins.trac.wordpress.org /browser/booking-calendar-contact-form/tags/1.2.59/dex_bccf.php
- plugins.trac.wordpress.org /browser/booking-calendar-contact-form/trunk/dex_bccf.php
- plugins.trac.wordpress.org /changeset