CyberRota Analysis
AI-GeneratedThe Booking for Appointments and Events Calendar plugin for WordPress versions prior to 2.4.7 is vulnerable due to a lack of authentication when processing its pending notification queue. This flaw allows unauthenticated users to trigger queued notifications and integration callbacks, potentially leading to unauthorized actions or data exposure. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.