Access violation vulnerability in WP Booking Calendar 10.10

The WP Booking Calendar plugin for WordPress has a security issue that affects all versions up to 10.10. This means that anyone, even without an account, can change their booking after it has been confirmed without having to verify their identity again. This can lead to unauthorized changes to bookings that have already been approved.

Detected in:

WP Booking Calendar fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.