CVE-2025-67574: WordPress Booking calendar, Appointment Booking System plugin <= 3.2.30 - Broken Access Control vulnerability
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.30.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67574?
CVE-2025-67574 is classified as a missing authorization vulnerability.
How do I fix CVE-2025-67574?
To fix CVE-2025-67574, update the wpdevart Booking calendar, Appointment Booking System to a version later than 3.2.30.
What impact does CVE-2025-67574 have?
CVE-2025-67574 allows attackers to exploit incorrectly configured access control security levels.
Which versions of wpdevart Booking calendar are affected by CVE-2025-67574?
CVE-2025-67574 affects wpdevart Booking calendar, Appointment Booking System versions up to and including 3.2.30.
Is CVE-2025-67574 related to any specific products?
Yes, CVE-2025-67574 is specifically related to the wpdevart Booking calendar and Appointment Booking System plugin.