SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-77704

LOW · CVSS 2.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Booking for Appointments and Events Calendar WordPress plugin prior to version 2.4.9 is vulnerable due to insufficient capability checks, allowing users to change appointment statuses arbitrarily. This can lead to unauthorized approvals of bookings and overwriting of other customers' appointment statuses, potentially disrupting scheduling and compromising the integrity of the booking system. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-77704
Severity
LOW
CVSS
2.7
EPSS
0.17%
WordPress

Original NVD Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment.