low · CVSS v3 3.7 · EPSS 0.00156
CVE-2026-39601
WPdevelop Booking Calendar plugin contains a race condition that can be triggered by concurrent booking requests, potentially allowing unaut
Overview
WPdevelop Booking Calendar plugin contains a race condition that can be triggered by concurrent booking requests, potentially allowing unauthorized manipulation of booking data. The flaw exists in all versions up to 11.8.4 and may lead to data corruption or service disruption.
Description
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.
Impact
Confidentiality: possible exposure of booking details. Integrity: unauthorized modification of booking records. Availability: potential service disruption due to corrupted data. Defenders: WordPress site administrators and plugin maintainers.
Remediation
Update Booking Calendar to version 11.8.5 or later. If an update is not immediately possible, disable concurrent booking submissions or implement request throttling to mitigate race conditions. Apply any vendor‑provided patch or configuration change that enforces proper synchronization.
Risk context
The CVSS v3 score of 3.7 and an EPSS of 0.00156 indicate a very low likelihood of exploitation; this vulnerability is low priority but should still be addressed in routine maintenance.
Affected products
- WPdevelop Booking Calendar
Scores
- Severity
- low
- CVSS v2
- 2.6
- CVSS v3
- 3.7
- CVSS v4
- —
- EPSS
- 0.00156